One FN Hits Password Could Unlock a Chain of Accounts
HEROIC's threat intelligence identified a stealer log file called "FN Hits" shared on Telegram in January 2025. The "FN" label typically refers to Fortnite, suggesting these 54 credential records were filtered specifically for Epic Games and Fortnite-related logins. Each entry contains an email address, a plaintext password, and the URL where the credential was stolen. Though the file is small, the gaming accounts it exposes often carry significant real-world value.
Plaintext Passwords: No Barrier Between Attacker and Account
The passwords in FN Hits are stored without any encryption or hashing. They are readable text strings that can be used immediately. For Fortnite accounts, this means attackers can access V-Bucks balances, rare skins, and linked payment methods within seconds of downloading the file. A single plaintext password is all it takes to hijack an account that may have hundreds of dollars of invested value.
What Was Exposed
- Email Addresses — Epic Games account identifiers, often personal email addresses
- Plaintext Passwords — fully readable and usable without decryption
- URLs — the login pages and services from which each credential was captured by malware
From One Gaming Password to Total Account Compromise
Gamers frequently reuse passwords across platforms. A Fortnite password that also works on your email account, Discord, Steam, or PlayStation Network gives an attacker a foothold that extends far beyond a single game. Credential stuffing attacks exploit exactly this behavior, testing each stolen pair against dozens of services automatically. The 54 credentials in FN Hits may be few in number, but each one is a potential thread that, when pulled, can unravel multiple connected accounts.
How Gaming Communities Become Malware Targets
The credentials in FN Hits were collected by infostealer malware running on infected devices. Gamers are frequent targets because they regularly download mods, custom tools, free V-Bucks generators, and game trainers from unofficial sources. Many of these downloads secretly bundle malware like RedLine, Lumma, or Vidar. Once installed, the trojan silently extracts every credential saved in the browser, packages them into log files, and sends them to the attacker. Files labeled by game name like "FN Hits" are then shared on Telegram to attract buyers interested in gaming accounts.
Check If Your Credentials Were Exposed
If you play Fortnite or have an Epic Games account, verify whether your credentials appear in this leak. HEROIC's data breach scanner searches across more than 400 billion compromised records to detect exposed emails and passwords. A quick scan can reveal whether your gaming password — and any other account that shares it — needs to be changed immediately.
Breach Breakdown
54 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds