The SoulSplit Leak: 6,297 Usernames and Passwords Exposed
HEROIC analysts identified a breach tied to SoulSplit, a private RuneScape server, dating to December 2013. The breach exposed 6,297 records containing usernames and passwords, some stored as SHA-1 hashes and others in plaintext.
Why a Mix of Plaintext and SHA-1 Passwords Is Especially Risky
Any password stored in plaintext is immediately readable by whoever holds the data, and SHA-1 isn't much of a backstop either since it can be cracked quickly with modern hardware. With this breach, essentially all 6,297 sets of credentials should be treated as fully exposed, whether they were hashed or not.
What Was Exposed in the SoulSplit Breach
- Usernames
- Passwords (SHA-1 and plaintext)
Why This Matters Beyond a Gaming Account
It's tempting to dismiss a private game server account as low value, but the username and password pair is frequently reused across email, social media, and other logins. Attackers scoop up small breaches like this one specifically to test those credentials against bigger, more valuable targets through credential stuffing.
How a Database Breach Like This Happens
This is classified as a database breach, meaning SoulSplit's user table, or a backup of it, was accessed directly. Smaller platforms like private game servers often run on outdated software with weaker security practices, which is reflected here in the mix of plaintext and weakly hashed passwords.
Check If You Were Affected by the SoulSplit Breach
If you ever played on SoulSplit, treat that password as compromised and check anywhere else you may have reused it. HEROIC's free breach scanner checks your email against more than 400 billion leaked records to help you find every account that needs a password change.
Breach Breakdown
6,297 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds