Identity Theft Just Got Easier Because of the OASIS Games Breach: 158,561 People at Risk
HEROIC analysts found a large credential dump tied to OASIS Games appearing on dark web marketplaces around June 18, 2023. The dataset covered 158,561 user accounts and included something that immediately raised alarms: passwords stored in plaintext. No hashing, no encryption, just raw passwords sitting alongside email addresses, ready to be used by anyone who downloaded the file.
Plaintext Passwords Open the Door to Instant Account Takeover
When passwords are stored in plaintext, attackers do not need to crack anything. They can log directly into any account where the user has not changed their password since the breach occured. Beyond OASIS Games itself, these credentials are partcularly dangerous because most people reuse passwords across multiple sites. That means a gaming account breach can quickly become a compromised email account, a hijacked bank login, or worse.
What Was Exposed in the OASIS Games (2023) Breach
- Email addresses
- Plaintext passwords
Why This Matters for Gamers and Beyond
Credential stuffing tools can automatically test these email and password pairs against hundreds of popular websites in minutes. If someone recieved the OASIS Games dump and tried those credentials against streaming services, financial platforms, or other games with linked accounts, the success rate would be significant. Gaming accounts also carry real monetary value through in-game currency, rare items, and linked payment methods, making this breach a direct financial threat.
How Credential Stuffing Works
Credential stuffing is an automated attack where criminals take known username and password pairs from one breach and try them on other services at scale. Tools like Sentry MBA and OpenBullet let attackers run millions of login attempts across dozens of sites simultaneously. Because so many users recycle the same passwords, even a breach from a smaller platform can unlock accounts at major financial institutions and social networks. The OASIS Games plaintext dump is exactly the kind of raw material these attacks depend on.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion exposed records, including the OASIS Games database. If your email was part of this breach, find out now at HEROIC.com before an attacker uses your credentials to get somewhere you really do not want them to go.
Breach Breakdown
158,561 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds