Minecraft Player Records Allegedly Offered for Sale

Hackers claimed to list millions of user records on underground forums via data stolen from compromised devices.

Updated on Oct. 2, 2026 in Cybersecurity

Isometric editorial illustration of a single server rack in a dark data center, representing digital security threats.
Threat actors have allegedly listed approximately 18 million Minecraft player records for sale on underground cybercrime forums, according to security researchers. AI Illustration. Upload story photo >

Live Poll

Do you trust gaming companies to keep your personal account information secure?

Threat actors have allegedly listed up to 18 million Minecraft player records for sale on cybercrime forums. Researchers determined the data was likely gathered through infostealer malware rather than a direct breach of company infrastructure.

Why it matters

The exposed information, which includes usernames and password hashes, poses a significant risk to players as it could be leveraged for credential stuffing attacks or targeted social engineering scams.

Researchers identified that the stolen data originated from 1,500 devices compromised in 2025 by Russian-origin malware. This malware was distributed through malicious GitHub repositories masquerading as legitimate Minecraft mods.

The players

Check Point Research

This is a cybersecurity intelligence organization that investigates global digital threats and identifies malware distribution patterns.

GitHub

This is a prominent software development platform where developers host code, which was used here to distribute malicious software.

Minecraft

This is a globally popular sandbox video game with approximately 212 million monthly active players.

The details

Hackers utilized two separate forum posts to advertise the data, which contains email addresses, usernames, and password hashes tied to only three unique servers. Investigations suggest that the primary source of the compromise was not the game itself but rather third-party mods hosted on GitHub.

Timeline

  1. Russian-origin malware compromised 1,500 devices during 2025.

  2. The findings regarding the alleged data breach were published on October 2, 2026.

The Tech Race

This incident highlights a shift toward infostealer malware that targets end-user devices rather than direct attacks on corporate gaming servers. It mirrors the trend of threat actors exploiting the trust gamers place in third-party modding ecosystems to bypass traditional perimeter security.

Players should exercise caution when downloading unofficial mods and avoid reusing passwords across different platforms to mitigate the risk of credential stuffing. Those who believe their information may be compromised should prioritize enabling multi-factor authentication on all associated accounts.

The takeaway

The security of gaming accounts often depends as much on the integrity of third-party mods as it does on official platform protections. Users are encouraged to source content only from verified creators to reduce the likelihood of malware infections.

Further reading

For more information on protecting your accounts from online threats, visit our Cybersecurity section.

Live Poll

Do you trust gaming companies to keep your personal account information secure?