ProLeague
We've been tracking the resurgence of older breaches appearing in modern combolists, a trend indicating that threat actors are recycling historical data for credential stuffing attacks. What caught our attention with the ProLeague breach wasn't the size—just 6,583 accounts—but the specific targeting of a niche gaming community and the age of the breach itself. The data, originally leaked in August 2018, has resurfaced on hacking forums, suggesting continued relevance for attackers targeting accounts within the virtual football gaming ecosystem.
ProLeague's 2018 Data: A Second Life in Combolists
The ProLeague breach involved the compromise of 6,583 user accounts from the German platform dedicated to "Pro Clubs" mode in virtual football games like EA SPORTS FC. The breach, which occurred in August 2018, exposed user email addresses and SHA-256 password hashes. The data was initially leaked on a prominent hacking forum and has recently reappeared in combolists, making it relevant again for potential credential stuffing attacks.
The re-emergence of this data is significant because it highlights the longevity of compromised credentials. Even years after a breach, exposed email and password combinations can still be effective in gaining unauthorized access to user accounts across various platforms. This is especially true for users who reuse passwords across multiple services. The fact that this relatively small breach is still circulating suggests that attackers are finding value in even older, niche datasets.
This matters to enterprises because it underscores the need for robust password management policies and proactive monitoring for compromised credentials. Even if a company wasn't directly affected by the ProLeague breach, employees who may have used the same credentials on their corporate accounts are now at increased risk. This breach is a reminder that older data breaches can still pose a significant threat, especially when combined with modern attack techniques like credential stuffing and password spraying.
- Total records exposed: 6,583
- Types of data included: Email addresses, password hashes (SHA-256)
- Sensitive content types: User credentials
- Source structure: Not specified (likely a database dump)
- Leak location(s): Hacking forums, combolists
- Date of first appearance: August 2018
External Context & Supporting Evidence
While there is limited mainstream media coverage of the original ProLeague breach from 2018, its presence in combolists indicates ongoing underground interest. Security researchers often track the circulation of such data on forums and Telegram channels dedicated to trading and sharing compromised credentials. The reappearance of this data aligns with broader threat trends involving the recycling of older breach data for credential stuffing attacks, as seen in numerous reports from cybersecurity firms focusing on botnet activity and account takeover prevention.
Breach Breakdown
6,583 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds