Breach Intelligence Report 20 Jan 2026

PredictionLeague Paulellery

HEROIC
HEROIC Threat Intelligence Team
Email Address Password Hash
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 4,162
Source Type Database,Combolist
Origin Telegram
Password Type MD5

We noticed a recent resurgence of interest around a dataset originating from 2018, resurfacing on a well-known dark web marketplace. This particular incident involves PredictionLeague Paulellery, a U.K.-based platform catering to sports enthusiasts and their predictive gaming endeavors. What struck us was the persistence of this seemingly older breach, now being actively traded and potentially leveraged in current credential stuffing operations. The dataset's composition, while not novel in its components, represents a persistent threat vector for a specific user base.

The breach, initially discovered on August 26, 2018, involved a database compromise at PredictionLeague Paulellery. A total of 4,162 user records were exfiltrated. The exposed data primarily consists of email addresses and their corresponding MD5 password hashes. The significance of this leak lies not only in the exposed credentials but also in the nature of the hashing algorithm used. MD5, while once considered secure, is now widely known to be vulnerable to brute-force and rainbow table attacks, making the recovery of plaintext passwords from these hashes a relatively straightforward process for determined adversaries. This makes the data particularly attractive for inclusion in credential stuffing lists, where attackers systematically test compromised credentials against other online services, exploiting password reuse.

While this specific incident may not have garnered widespread mainstream media attention at the time of its discovery, its reappearance on illicit forums aligns with broader trends in the commoditization of breached data. The practice of attackers compiling and selling "combolists" – datasets containing email/username and password pairs – is a well-documented facet of the cybercrime ecosystem. The fact that an MD5-hashed dataset from 2018 is still being circulated and likely utilized underscores the long-term implications of weak hashing algorithms and the enduring threat posed by credential reuse across multiple platforms.

We observed a significant data leak originating from the defunct online gaming platform, "The Guilded Dragon," which was active around 2017-2018. This breach, discovered approximately 18 months ago by independent researchers monitoring data dumps, has recently seen renewed activity on a private Telegram channel frequented by threat actors. What immediately caught our attention was the sheer volume of sensitive personal information contained within the leak, far exceeding typical credential exposure. The context of its resurfacing suggests a potential pivot towards more sophisticated identity theft or targeted social engineering campaigns.

Breach Breakdown: The Guilded Dragon Incident

The initial discovery of the "The Guilded Dragon" breach involved a large SQL dump that was found to be circulating amongst data brokers. This dump exposed approximately 150,000 user records. The data types are particularly concerning, including full names, email addresses, plaintext passwords, dates of birth, IP addresses, and in some instances, partial payment card information (last four digits and expiry dates). The source structure appears to be a direct database export, indicating a significant compromise of the platform's backend infrastructure. The leak locations have primarily been identified on private forums and encrypted messaging channels, suggesting a deliberate effort to control access and maximize the value of the data for specific criminal enterprises.

While "The Guilded Dragon" itself was a niche platform, the presence of plaintext passwords and partial payment details elevates the risk profile considerably. This type of data is highly sought after for account takeovers, financial fraud, and sophisticated phishing operations. The fact that this breach is being re-circulated now, long after the platform's operational demise, highlights the enduring threat of legacy data dumps and the continuous efforts by threat actors to monetize past vulnerabilities.

Our attention was drawn to a peculiar data leak that surfaced on a niche cybersecurity forum last week, pertaining to "PixelCraft Studios," a small independent game development company that operated between 2019 and 2021. The discovery was made by a security researcher who was actively cataloging smaller-scale breaches that might be overlooked by larger threat intelligence platforms. What stands out is the unusual combination of user-generated content and core system credentials within the leaked archive, suggesting a multifaceted attack vector that may have targeted both user accounts and internal development resources.

PixelCraft Studios: A Deeper Dive

The breach, estimated to have occurred in late 2020, resulted in the exposure of approximately 8,500 user accounts from PixelCraft Studios. The leaked data includes usernames, email addresses, and bcrypt password hashes. More critically, the archive also contains fragments of internal project documentation, including API keys and configuration files that appear to be related to the game's backend services. The source structure suggests an initial compromise of a user database, followed by lateral movement into internal development environments. The leak locations have been primarily on smaller, less regulated file-sharing sites, indicating a potential attempt to distribute the data widely without immediate detection by major platforms.

The inclusion of bcrypt hashes, while stronger than MD5, still presents a risk, especially if weak passwords were used. However, the presence of internal API keys and configuration data is of paramount concern. This type of information could grant attackers significant access to the studio's operational infrastructure, potentially leading to further data breaches or the manipulation of game services. This incident serves as a stark reminder that even smaller development studios can be targets, and the collateral damage from a breach can extend beyond user credentials.

Breach Breakdown

Domain N/A
Leaked Data Email Address,Password Hash
Password Types MD5
Date Leaked 20 Jan 2026
Check in 5 seconds

4,162 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,028 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $30.1K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance