New Game
We noticed a significant data leak surfacing on a well-known underground forum, specifically impacting users of the Chilean gaming information portal, New Game. The dataset, which appeared on August 26, 2018, contained a concerning volume of user credentials. What struck us was the relatively low but still impactful number of affected accounts, suggesting a targeted or contained incident rather than a broad-spectrum compromise. The nature of the leaked data, primarily email addresses and their associated password hashes, points towards a common but persistent attack vector.
The breach breakdown reveals that 6,485 user records were exfiltrated from New Game. The compromised data primarily consists of email addresses and their corresponding password hashes, specifically in the MD5 format. This type of hash is particularly vulnerable to brute-force attacks and rainbow table lookups, meaning the exposed passwords are at a high risk of being deciphered. The source structure indicates a likely database compromise, where the user table was directly accessed. The leak location on a prominent hacking forum signifies an intent to distribute or monetize the stolen credentials, potentially for further malicious activities such as account takeovers on other platforms or phishing campaigns. This incident falls under the category of a database breach, with the resulting data being utilized in the creation of combolists.
While this specific breach did not generate widespread mainstream media attention at the time, it is emblematic of a recurring pattern of credential stuffing attacks that leverage leaked databases. The use of MD5 hashing, a cryptographic hash function considered insecure by modern standards, is a critical vulnerability. Cybersecurity research consistently highlights the ease with which MD5 hashes can be cracked, especially when combined with common password patterns. This incident serves as a stark reminder for organizations to regularly audit their data security practices and prioritize stronger hashing algorithms like bcrypt or Argon2 to protect user credentials.
Breach Breakdown
6,485 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds