Dark Web Intel: 60K Records From The Trading Game Database Dump
HEROIC analysts uncovered the The Trading Game breach while monitoring dark web forums and underground marketplaces for freshly circulated Australian financial platform credentials. In March 2018, The Trading Game, an Australian mentorship and education platform for traders, suffered a database breach that exposed 60,176 user records. The scope of this breach is seperate from typical credential dumps in a troubling way: the exposed data went far beyond just email and password, including full names, phone numbers, IP addresses, and in some cases plaintext passwords stored without any protection whatsoever.
Why Financial Trader Data Is a Prime Target for Fraud
Users of The Trading Game are investors, traders, and finance-minded individuals. That profile makes this breach particularly dangerous. Attackers who obtain full names, phone numbers, email addresses, and passwords can craft highly convincing phishing calls and emails impersonating brokers, financial advisors, or the platform itself. With IP addresses also exposed, fraudsters can narrow down a target's approximate location and tailor social engineering attacks accordingly. Credential stuffing using the exposed logins can then be used to access brokerage accounts, banking apps, and investment platforms where real money is at stake. Financial fraud and identity theft are the most likely outcomes for affected users.
What Was Exposed in the The Trading Game Breach
- Email Address
- Phone Number
- Password Hash
- Plaintext Password
- Username
- First Name
- Last Name
- IP Address
Why This Australian Financial Platform Breach Still Poses Risks
Data from The Trading Game is actally more dangerous now than it was at the time of the breach. Attacker tooling has improved dramatically, meaning even bcrypt hashes that were once considered secure can be cracked over time with dedicated hardware. Combined with the plaintext passwords also found in this dataset, criminals have a rich combination of immediately usable and potentially crackable credentials pointing to real people who manage financial accounts. Credential stuffing attacks using Australian user data regularly target banking platforms and trading apps across the region. Anyone who was a member of The Trading Game and reused their credentials elsewhere should treat those accounts as compromised.
How a Database Breach Works
A database breach happens when an attacker finds a way into the backend storage system of a website or platform. This can happen through a security vulnerability in the website's code, an exposed database port, or stolen administrator login credentials. Once inside, the attacker copies the user records and exports them for sale or personal use. In the case of The Trading Game, the inconsistent mix of bcrypt hashes and plaintext passwords in the same database suggests different security practices were applied to different user groups, creating gaps that were ultimately exploited.
Check If Your Data Was Exposed
HEROIC's free breach scanner is powered by a database containing more than 400 billion compromised records. If you or someone you know registered on The Trading Game, you can search your email address right now to confirm whether your information appeared in this breach or any other known data leak. Visit HEROIC today for a free check and take the first step toward protecting your financial accounts and personal identity.
Breach Breakdown
60,176 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds