Researchers Link the Suba Games Breach to 2,765 Stolen Accounts
HEROIC analysts monitoring dark web credential markets identified the Suba Games breach as part of a broader aggregation of gaming platform leaks. The breach occured in September 2016, exposing 2,765 user accounts from this Canadian online gaming portal at subagames.com. Researchers found the data circulating in private Telegram channels where credential stuffing operators trade older database dumps. While the record count is relatively small, the vB (vBulletin) password hashes included in the dump make this breach partcularly useful to attackers targeting gamers who reuse passwords across multiple platforms.
Why vBulletin Password Hashes From Suba Games Are a Threat
vBulletin password hashes, when not properly salted, are accessable to cracking tools that can test millions of password combinations per second. Attackers who crack these hashes gain working credentials that they then test against Steam, Epic Games, EA, and other gaming platforms where the same email and password combination may still be active. Gaming accounts with in-game currency, rare items, or linked payment methods are high-value targets. The Suba Games data gives attackers a direct path to account takeover on platforms far more valuable than the original source.
What Was Exposed in the Suba Games Breach
- Email addresses
- Usernames
- vBulletin password hashes
How the Suba Games Breach Enables Gaming Account Takeovers
Researchers have beleived for years that gaming communities are disproportionately targeted by credential stuffing attacks because gamers frequently reuse passwords. Once attackers crack the vB hashes from Suba Games, they load the results into automated tools that attempt logins across dozens of gaming services simultaneously. Successful matches are sold on dark web marketplaces as ready-to-use gaming accounts. Victims face identity theft, financial fraud through linked payment methods, and the loss of years of in-game progress. The Suba Games data has recieved renewed interest from threat actors as gaming account fraud continues to grow.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a company's backend database, usually through a software vulnerability or compromised admin credentials. The attacker copies the stored user data, including account information and password hashes, then disappears without triggering alerts. That data is later sold or posted in criminal communities, where it fuels automated attack campaigns that can target victims months or years after the original breach took place.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address against more than 400 billion records, including the Suba Games breach and thousands of other known data leaks. Visit HEROIC.com to run a free scan and find out whether your credentials are circulating on the dark web right now.
Breach Breakdown
2,765 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds