Dark Web Intel: 262,192 Credentials From the SofaScore Database Dump
HEROIC analysts surfaced dark web activity surrounding a database breach affecting SofaScore, a Croatian sports scores and statistics platform operating at sofascore.com. The breach, dated July 2021, exposed 262,192 records containing email addresses, first names, last names, and password hashes. The data has been recieved with renewed interest on underground forums, with threat actors combining it with other sports and betting platform leaks to build detailed victim profiles.
How Stolen SofaScore Credentials Fuel Sports Betting Account Takeover
Email addresses and password hashes from sports platforms like SofaScore are particularly attractive to threat actors targeting sports betting and fantasy sports accounts. Attackers validate cracked credentials against betting platforms where the same email and password combination may unlock accounts containing real funds. Full names increase the effectiveness of targeted phishing emails, making them appear seperate from generic spam and convincing victims to reveal additional information or reset credentials on attacker-controlled pages.
What Was Exposed in the SofaScore Breach
- Email Address
- First Name
- Last Name
- Password Hash
Why the SofaScore Breach Remains an Active Threat
Breaches from 2021 do not expire. The SofaScore dataset has occured in multiple underground forum discussions years after the initial leak, with threat actors packaging it alongside other sports and gambling breaches for credential stuffing campaigns. Users who never changed their SofaScore password after the breach remain vulnerable to account takeover on any platform where they reused that password. The full name data combined with email addresses enables convincing social engineering attacks and identity fraud targeting sports fans and bettors.
How Database Breaches Work
A database breach occurs when attackers gain unauthorized access to a platform's backend database, typically through SQL injection, misconfigured access controls, or compromised administrative credentials. Once inside, they extract user tables containing personal information and credentials. The stolen data is then sold or published on dark web forums, where other threat actors purchase and use it for credential stuffing, phishing, and account takeover attacks. Sports and entertainment platforms are recurring targets because their user bases often reuse passwords across betting and social accounts.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records, including data from the SofaScore breach, to tell you exactly what personal information of yours has been exposed. Run a free scan now to find out if your email address, name, or password are at risk and protect your accounts before attackers exploit them.
Breach Breakdown
262,192 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds