Stolen user account database survived online for more than ten days

Jul 24, 2012 15:14 GMT  ·  By

It’s been more than four months since the attack on Gamigo’s servers, a German publisher of free-to-play online games, but the breach is still in the news as the hackers leaked online more than eight million credentials (hashed passwords).

The leak had been online as early as July 6, and in half an hour someone already posted “found 94%” which could mean that they managed to decrypt the passwords.

However, the database was spotted just about a week ago when PwnedList spotted a tweet about Gamigo hashes having been dumped.

PwnedList is an online service that gathers databases of compromised credentials to allow the average users to check if their accounts have fallen in the wrong hands. They managed to get the Gamigo database, so you can check if your credentials have been included in the leak.

Following the attack, Gamigo informed their users about the breach and forced a password reset, but the risk of users having the same credentials for multiple accounts still remains.