Gamers Beware: The Unofficial Tex Murphy Breach Dumped 10K Accounts
HEROIC analysts identified the Unofficial Tex Murphy breach while reviewing a compilation of older forum database leaks surfacing in aggregated credential stuffing lists. The incident occured in August 2018 and exposed 10,322 user records from a United States-based fan forum dedicated to the Tex Murphy detective game franchise. What made this case accessable for deeper analysis was the transparency of the breach data, which revealed a concerning mix of weak hashing algorithms including SHA1, Drupal7, and PHPass, all of which are considered crackable with modern tooling.
Weak SHA1 and PHPass Hashes From Unofficial Tex Murphy Are Crackable Today
SHA1 is no longer considered secure for password storage, and PHPass is similarly outdated. Attackers with access to this breach data can run the hashes through widely available cracking tools using dictionary attacks and rainbow tables. The process is fast and recieved wisdom in attacker communities means these techniques are well documented and automated. Cracked passwords are then fed into credential stuffing pipelines targeting email, gaming, streaming, and financial platforms, putting affected users at real risk of account takeover and identity theft.
What Was Exposed in the Unofficial Tex Murphy Breach
- Email Address
- Password Hash
Why Gaming Fan Forum Breaches Put Gamers at Risk Across All Platforms
Gamers partcularly tend to reuse passwords across fan forums, gaming platforms, and broader online services. An email-password pair from a 2018 Tex Murphy fan forum could still unlock a Steam account, an Epic Games account, or a PayPal account if passwords were reused. Credential stuffing, account takeover, in-game financial fraud, and identity theft are all plausible outcomes. The small size of this breach makes it easy to overlook, but attackers bundle datasets like this into massive combined lists that make even small breaches part of large-scale attacks.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to the database powering a website or web application. Fan forums running older software like phpBB or Drupal are frequent targets because they often go unpatched for extended periods. Attackers exploit known vulnerabilities, extract user tables, and distribute the data across underground markets. Once published, that data enters a long-lived cycle of repackaging and resale that keeps it relevant for years or even decades after the original incident.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email against more than 400 billion records, including the Unofficial Tex Murphy breach and thousands of other forum and platform incidents. Run your free scan at HEROIC right now and find out if your credentials are already in attacker hands.
Breach Breakdown
10,322 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds