Fantase Game Data Breach: 2.27M U.S. Records With Plaintext Passwords
2.27 Million Fantase Game Passwords Were Stored in Plaintext -- And Then Stolen
In August 2018, Fantase Game -- a U.S.-based gaming website at fantasegame.com -- suffered a data breach that exposed 2,269,829 user records. What makes this breach stand out from nearly every other incident in the August 2018 cluster is a single catastrophic security failure: the passwords were stored in plaintext. No hashing. No encryption. Just the raw password exactly as each user typed it, sitting in a database column, waiting to be stolen. When attackers obtained the Fantase Game database, they got 2.27 million email-and-password pairs that required exactly zero cracking effort to use.
Fantase Game Data Breach: Breach Summary
- Records Exposed: 2,269,829
- Data Types: Email addresses, plaintext passwords
- Breach Type: Database breach
- Country Affected: United States
- Date Leaked: August 2018
Plaintext Storage: The Worst Possible Outcome for Users
Password hashing exists for one reason: to ensure that even if a database is stolen, attackers cannot immediately read the passwords. MD5 is weak. SHA1 is weak. PHPass is outdated. But all of them are infinitly better than plaintext, which offers zero protection whatsoever. When Fantase Game stored its users' passwords in plaintext, it removed the only technical barrier between a stolen database and full credential exposure. Every Fantase Game user whose account appears in this breach had their exact, current, ready-to-use password handed directly to whoever obtained the data. No cracking required. No GPU farms. No rainbow tables. Just a database query.
The Credential Stuffing Multiplier at 2.27 Million Scale
With 2.27 million email-plaintext password pairs, the Fantase Game breach represents a ready-made credential stuffing arsenal. Automated tools can take a file of email:password pairs and systematicly test them against hundreds of major websites simultaneously -- streaming services, banks, email providers, retail platforms. Even if only 5% of Fantase Game users reused their password on another service, that's over 113,000 accounts that could be compromised with no additional effort beyond running the breach file through a stuffing tool. The scale and plaintext nature of this breach make it one of the more potentialy impactful incidents from August 2018, despite receiving less attention than large enterprise breaches of the same era.
Check if Your Email Was in the Fantase Game Breach
HEROIC's free breach scanner searches across more than 400 billion exposed records, including the Fantase Game breach. Enter your email to see if your credentials appear in this database. If your email is in this breach and you used the same password on any other platform, that password should be considered completly compromised and changed immeditaly -- there is no cracking barrier between the attacker and your exact password in this dataset.
Breach Breakdown
2,269,829 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds