Escudodigital 18 Million Minecraft Player Records Allegedly Breached and Sold
Article Content
- •Hackers claim to sell 18 million Minecraft player records.
- •Data includes usernames, emails, and password hashes from specific servers.
- •Credential stuffing poses a significant risk for affected players.
Hackers are claiming to sell up to 18 million records of Minecraft players on dark web forums. Cybernews researchers analyzed samples of around 1,000 records, which included usernames, email addresses, and some password hashes. The data appears to originate from at least three specific Minecraft servers, ruling out a breach of Mojang Studios' or Microsoft's central servers. The presence of email addresses in databases like Have I Been Pwned suggests the data was harvested using infostealer malware. The exact age of the dataset is unknown, and it remains unclear whether the claims of 18 million or 9 million records are accurate. Microsoft has not publicly commented on the incident. The primary risk for affected players is credential stuffing, where attackers use leaked credentials to access other accounts.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What data was exposed?
How did the breach occur?
What should affected players do?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…