U.S. Gamers Targeted: Valorant Stealer Log Exposes 77,622 Passwords
In April 2023, HEROIC analysts discovered a stealer log circulating on Telegram under the name "97K User_Pass Gaming Valorant." The dataset specifically targeted gaming accounts and contained 77,622 unique records extracted from compromised devices, including email addresses, plaintext passwords, and the URLs of gaming platforms where those credentials were used. The focus on Valorant and gaming services indicates a deliberate campaign aimed at the gaming community.
Why Plaintext Gaming Passwords Are Immediate Targets
Every password in this stealer log was captured in plaintext, meaning attackers can use them instantly without any decryption or cracking process. The moment this dataset was shared on Telegram, every credential inside it became a live key to someone's account. For gaming accounts, this means immediate risk of unauthorized access, stolen in-game items, and hijacked profiles.
Gaming accounts are high-value targets on underground markets. Accounts with rare skins, high ranks, or linked payment methods can sell for hundreds of dollars. Attackers who obtain plaintext credentials from stealer logs often move within minutes to claim and resell compromised accounts before victims even realize they have been breached.
Because these passwords require zero processing to exploit, the window between exposure and account takeover is dangerously short. Anyone whose credentials appear in this dump and who has not updated their passwords since April 2023 remains at risk.
What Was Exposed in the Valorant Gaming Dump
- Email Addresses — Login emails associated with Valorant and other gaming platforms, giving attackers direct access to verified account identifiers used across Riot Games and related services.
- Plaintext Passwords — Unencrypted passwords harvested from browsers on infected machines, requiring no additional effort to use for unauthorized logins on gaming platforms and any other service sharing the same credentials.
- URLs — The exact login pages and gaming service endpoints where each credential was stored, allowing attackers to precisely match passwords to their corresponding platforms.
Why 77,622 Compromised Gaming Credentials Pose a Wider Threat
While this leak targets gaming accounts, the real danger extends far beyond Valorant. Studies consistently show that a majority of users recycle the same password across multiple services. A password used for a Valorant account is often the same one protecting an email inbox, a bank login, or a work application. Credential stuffing tools can test these 77,622 combinations against thousands of platforms in a matter of hours.
Attackers know this. Once a gaming credential works on one platform, automated tools immediately test it against email providers, social media sites, cloud storage services, and financial institutions. A single compromised Valorant password can become the entry point for a much broader account takeover campaign.
For U.S. gamers specifically, the intersection of gaming accounts with linked payment methods, personal email addresses, and social media profiles creates a particularly rich attack surface for identity theft and financial fraud.
How Stealer Logs Capture Gaming Credentials
Infostealer malware is the engine behind datasets like this one. Programs such as RedLine, Raccoon, and Vidar infiltrate devices through common vectors that gamers encounter regularly: fake game cheats, cracked software, mod downloads, and phishing links shared in gaming communities and Discord servers.
Once active on a device, the malware silently extracts every credential saved in web browsers, including gaming platform logins, email passwords, and any other stored authentication data. It packages this information into structured log files that are then uploaded to command-and-control servers and distributed through Telegram channels and dark web forums.
The "97K Valorant Gaming" dataset was compiled through exactly this process. The credentials are not guesses or recycled from older breaches. They were captured directly from real users' devices, making them highly accurate and immediately dangerous.
Check If Your Credentials Appear in This Leak
If you play Valorant or use other gaming platforms, your login credentials may be part of this stealer log. HEROIC provides a free breach scanner that checks your email address against this dataset and more than 400 billion other exposed records from known breaches and stealer log distributions.
Running a scan takes only seconds and can reveal whether your credentials have been circulating among threat actors. If your email appears in the results, change your passwords immediately on all gaming platforms and any other service where you used the same credentials, and enable two-factor authentication on every account that supports it.
Breach Breakdown
77,622 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds