Skip to content
18 Million Minecraft Player Records Allegedly Breached and Sold

18 Million Minecraft Player Records Allegedly Breached and Sold

First seen 5 Oct 2026, 13:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 14:26 UTC
  • •Hackers claim to sell 18 million Minecraft player records.
  • •Data includes usernames, emails, and password hashes from specific servers.
  • •Credential stuffing poses a significant risk for affected players.

Hackers are claiming to sell up to 18 million records of Minecraft players on dark web forums. Cybernews researchers analyzed samples of around 1,000 records, which included usernames, email addresses, and some password hashes. The data appears to originate from at least three specific Minecraft servers, ruling out a breach of Mojang Studios' or Microsoft's central servers. The presence of email addresses in databases like Have I Been Pwned suggests the data was harvested using infostealer malware. The exact age of the dataset is unknown, and it remains unclear whether the claims of 18 million or 9 million records are accurate. Microsoft has not publicly commented on the incident. The primary risk for affected players is credential stuffing, where attackers use leaked credentials to access other accounts.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
Cybernews reports on data breach claims
Cybernews researchers analyzed samples of alleged Minecraft player records offered for sale on dark web forums.
Cybernews
2026-10-05
Escudodigital covers ongoing breach claims
Escudodigital reports on the sale of Minecraft player records and the analysis of the data by Cybernews researchers.
Escudodigital

More articles in this cluster (2)

Common questions

What data was exposed?
The exposed data includes usernames, email addresses, and some password hashes from Minecraft players.
How did the breach occur?
The breach likely resulted from infostealer malware, possibly through malicious modifications or add-ons on multiplayer servers.
What should affected players do?
Players should change their passwords and enable two-factor authentication on their accounts to mitigate risks.