Data breach
17173
- Records
- 18,236,045
- Breach date
- 28 December 2011Estimated
- Added
- 1 December 2024
What was exposed
3 types of data · 1 puts you at serious risk
- Email addresses18,236,045
- Usernames18,236,037
- Passwords18,233,755
About this breach
In late December 2011, a database belonging to 17173.com, one of China's largest gaming information portals, surfaced among a wave of stolen credentials from major Chinese websites. The dataset tied to 17173 contains roughly 18.2 million records, each pairing an email address with a password and a username or nickname. The leak was part of a broader series of breaches that hit Chinese internet services at the end of 2011, when attackers dumped millions of user records from sites including gaming and community platforms. Mozilla Monitor, which tracks publicly known breaches, dates the 17173 incident to December 28, 2011, though researchers have noted that data from the Chinese breach wave was difficult to verify definitively at the time it circulated.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
December 28, 2011: Mozilla Monitor records the 17173 breach as occurring on this date, during a wave of large-scale leaks affecting Chinese websites.
April 28, 2018: The breach was added to Mozilla Monitor's public database after being discovered and verified by that service.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, passwords, and usernames or nicknames. The investigation team indexed 18,236,045 records in total, including 18,236,045 email addresses, 18,236,037 usernames, and 18,233,755 passwords. Academic researchers who later analyzed the 17173.com dataset, including a team at Zhejiang University studying real-world password leaks, catalogued it as a gaming-site dataset of about 18.3 million passwords containing roughly 5.2 million unique values.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main danger from a leak of this kind is password reuse. Most people reuse the same passwords, or small variations of them, across many websites. A 2019 study of leaked Chinese password datasets, published in a peer-reviewed review of password-guessing research, found that a large share of 17173.com passwords could be guessed within a few hundred attempts using only username information, which suggests many users chose weak or predictable passwords.
An attacker holding an email address and password from 17173 can try those credentials against email providers, social media, banking, shopping, and other gaming sites. This technique, known as credential stuffing, often succeeds because a password exposed on one site still works on another. Exposed email addresses also become targets for phishing, since attackers can send convincing messages that reference accounts or services the recipient actually uses. Users of the gaming portal could additionally face account takeover, with in-game items, currency, or linked payment details at risk.
What Should You Do If You Were Affected?
Change your password on 17173.com if you still have an account there, and on any other site where you used the same or a similar password.
Prioritize email accounts: if the password you used on 17173 protected your primary email, reset that immediately, because email access lets attackers reset nearly everything else.
Turn on two-factor authentication wherever it is offered, especially for email, gaming, and payment accounts.
Check whether your email address appears in this or other breaches using the search tool.
Be cautious with unexpected emails or messages that ask you to log in or verify account details; attackers often use leaked addresses for phishing campaigns.
Consider using a password manager to create a unique password for every account going forward.
In the news
- Mozilla Monitor, breach details for 17173monitor.mozilla.org (opens in a new tab)
- A Systematic Review on Password Guessing Tasks (PMC)pmc.ncbi.nlm.nih.gov (opens in a new tab)
- A Large-Scale Empirical Study on the Crackability, Correlation, and Security of Real-World Passwords (Zhejiang University)nesa.zju.edu.cn (opens in a new tab)
