One Password, Total Exposure: 24,931 Gaming Base Logins Leaked
HEROIC analysts uncovered a stealer log collection labeled "105k Gaming Base" that was shared through a Telegram channel in May 2023. Despite the name suggesting 105,000 entries, the verified dataset contains 24,931 unique compromised records. Each record includes email addresses, plaintext passwords, and the URLs of websites where those credentials were used, with a particular concentration on gaming platforms and related services.
Why Plaintext Passwords Are a Gift to Attackers
The passwords in the 105k Gaming Base dump require zero effort to exploit. Stored in plaintext with no hashing or encryption, each credential is immediately usable. An attacker does not need specialized hardware or password-cracking software — they simply read the password and log in.
Gaming accounts are especially valuable targets because they often hold stored payment methods, digital currency, and rare in-game items worth real money. A single compromised gaming login can lead to financial theft, loss of digital assets accumulated over years, and unauthorized purchases charged to linked credit cards.
What Was Exposed in the Gaming Base Dump
- Email Addresses — Account identifiers used across gaming platforms, forums, and related services, which also serve as targets for phishing campaigns.
- Plaintext Passwords — Fully readable, unencrypted passwords harvested from browsers and password managers on infected devices.
- URLs — The exact login pages and services where credentials were captured, revealing which platforms each victim frequented.
Why 24,931 Compromised Accounts Multiply Quickly
Gamers frequently use the same email and password combination across multiple platforms — from Steam and Epic Games to Discord, Twitch, and associated email accounts. Studies show that password reuse rates exceed 60% among general internet users, and gaming communities are no exception. Each of these 24,931 credential pairs is a potential key to multiple accounts.
Credential-stuffing bots can test thousands of login combinations per minute across dozens of services simultaneously. Once an attacker confirms a working credential on one platform, they systematically try it everywhere else. A single gaming password reused on an email account can give an attacker the ability to reset passwords on every connected service.
How Stealer Logs Capture Gaming Credentials
Infostealer malware often spreads through gaming-related vectors: fake game cracks, cheat tools, mod installers, and pirated software. Once installed, the malware silently extracts saved passwords from every browser on the device, along with session cookies, autofill data, and cryptocurrency wallets.
The harvested data is bundled into log files and sent to command-and-control servers. From there, logs are aggregated into collections like the 105k Gaming Base and distributed through Telegram channels where they are sold cheaply or given away entirely. By the time a victim notices anything unusual, their credentials may have already been traded among multiple threat actors.
Check If Your Credentials Were Exposed
If you have ever downloaded game modifications, free software tools, or saved passwords in your browser while visiting gaming sites, your credentials may be part of this or similar stealer log collections. The risk extends beyond gaming — any password saved on a compromised device is at stake.
Use HEROIC's free breach scanner to search for your email address or passwords across the 105k Gaming Base dump and over 400B+ compromised records in our database. Discovering exposure early gives you the opportunity to change passwords and enable two-factor authentication before attackers strike.
Breach Breakdown
24,931 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds