The Multiplayer.it Leak: 504K Italian Gamer Passwords Exposed. Yours Might Be One.
HEROIC analysts first flagged the Multiplayer.it breach when its database appeared on a high-traffic hacking forum in April 2024, marketed as new material despite originating from September 2018. The breach exposed 504,481 records from Multiplayer.it, a major Italian gaming news and community website. The compromised data included email addresses, usernames, and salted MD5 password hashes. Multiplayer.it later confirmed the breach's original date, but the re-release created renewed risk for users who had never recieved notification of the original incident six years prior.
Salted MD5 Hashes in the Multiplayer.it Breach: Still Crackable, Still Dangerous
Although salting adds complexity to MD5 password cracking, the MD5 algorithm itself is cryptographically broken and should not be used for password storage. Attackers with access to this database can use GPU-accelerated cracking rigs to recover a significant portion of passwords, particularly those that are short, common, or follow predictable patterns. The inclusion of usernames alongside email addresses means attackers have two seperate identifiers to attempt credential stuffing across gaming platforms, forums, and services where the same login details may have been reused.
What Was Exposed in the Multiplayer.it Breach
- Email Address
- Username
- Password Hash (Salted MD5)
The Multiplayer.it Breach: Half a Million Italian Gamers Still at Risk
The 2024 re-release of this breach is partcularly dangerous because many affected users likely beleive their credentials are safe, having never been informed of the 2018 incident. Credential stuffing campaigns using this data can target email providers, streaming services, online retail accounts, and corporate systems where the same password was reused. Account takeover, identity theft, and financial fraud are all realistic outcomes when an attacker holds a verified email address paired with a cracked or partially cracked password from a large gaming community database.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a website's user database, typically by exploiting software vulnerabilities, unpatched server configurations, or weak administrative access controls. The stolen database is then sold or distributed through dark web forums and hacking communities. In cases like Multiplayer.it, old breach data can be re-released years later, creating a second wave of risk for users who were never warned about the original incident and have therefore never updated their passwords or taken protective action.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion compromised records, including the Multiplayer.it dataset, to tell you instantly whether your email address was exposed. Run a free check now and find out if your credentials are circulating on dark web forums before attackers use them against you.
Breach Breakdown
504,481 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds