The THZ Clan Leak Contains More Accounts Than the Entire Population of Liechtenstein
HEROIC analysts flagged the THZ Clan breach in January 2018, when a database belonging to the U.S.-based gaming community site was found exposed containing records for 46,304 registered users. The compromised data included email addresses and MD5 password hashes. What is beleived to make this incident accessable to a wide range of attackers is the use of MD5, a hashing algorithm so outdated that modern cracking hardware can test billions of combinations per second against it, making many of these passwords effectively recoverable.
How Cracked MD5 Hashes Let Attackers Into Your Other Accounts
MD5 password hashes are widely considered broken by security researchers. When attackers get a list of MD5 hashes like those leaked from THZ Clan, they run them through precomputed lookup tables called rainbow tables, which can match common passwords to their hashes almost instantly. Once they crack your THZ Clan password, they try that same email and password combination on Gmail, Steam, Xbox Live, PayPal, and dozens of other services. The success rate is high because most people reuse passwords, and a single cracked hash from a small gaming site can open doors across your entire digital life.
What Was Exposed in the THZ Clan Breach
- Email Address
- Password Hash (MD5)
Why Weak Hashing in Gaming Communities Has Real-World Consequences
THZ Clan was a niche community focused on team-based games like Tribes and Call of Duty, but the damage from this breach extends far beyond gaming. Users who registered with their work email or reused a common password are at risk of credential stuffing attacks against corporate systems, financial accounts, and email providers. Even accounts created years ago remain useful to attackers because people rarely change passwords proactively. The combination of MD5 hashing and long-term password reuse habits makes this type of breach a persistent threat long after the original incident.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a website's backend servers and copies the user database. For smaller community sites like THZ Clan, this often happens through outdated software with known vulnerabilities or poorly secured database configurations. The attacker downloads the entire user table, which includes whatever format the site used to store passwords. If that format is MD5 without any added salt, the passwords are relatively easy to recover using freely available cracking tools and precomputed tables.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records to check whether your email address appeared in the THZ Clan breach or any other known data leak. Run a free check at HEROIC today and get a complete picture of your exposure before attackers use it against you.
Breach Breakdown
46,304 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds