More Than 131,000 Minecraft Accounts Leaked in Stealer Log
In May 2023, a file called "140k Minecraft target" appeared on a Telegram channel that trades in stolen login data. The actual count inside the file was 131,449 records, each one an email address paired with a plaintext password and the web address the login was captured from. This was not a breach of Mojang or Minecraft's own servers. It is a stealer log, a batch of credentials lifted straight from devices already infected with information-stealing malware, in this case apparently targeting players logging into Minecraft-related accounts.
Why This Minecraft-Linked Leak Is Dangerous
The passwords in this file were captured and stored in plaintext, not hashed or encrypted in any way. That means whoever holds this log can read every password exactly as the account owner typed it. Paired with the matching email and the exact site each login belongs to, this gives an attacker a ready-to-use set of working credentials rather than something they need to crack.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs showing where each login was captured
Why This Matters
Gaming accounts are frequently tied to the same email and password combination people use for far more sensitive accounts, like email providers, banking apps, and shopping sites. When a log like this circulates, attackers run the same email and password pairs against dozens of other services in bulk, a method called credential stuffing. A Minecraft login being reused elsewhere can quickly turn into a hijacked email account, stolen payment details, or a full identity theft case.
How Stealer Logs Like This One Are Built
This data was almost certainly harvested by infostealer malware, malicious code that gets installed through pirated game mods, cracked launchers, cheat tools, or fake downloads, all common bait for Minecraft players. Once active, the malware pulls saved passwords and autofill data straight out of the browser and sends it back to whoever controls the malware. That stolen batch is then bundled into a log file and traded or dumped on Telegram, which is exactly how this file surfaced.
Check If You Are Affected
With more than 131,000 records in this single log alone, and countless similar files circulating, checking your own exposure directly is the only reliable way to know where you stand. HEROIC's free breach scanner checks your email against a database of over 400 billion leaked records, including stealer logs like this one, and tells you immediately if you were exposed. If your details show up, reset that password everywhere it was reused and enable multi-factor authentication on every account that offers it.
Breach Breakdown
131,449 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds