Data breach
2games.com
- Records
- 3,425,967
- Breach date
- 1 January 2020Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses3,425,967
- Passwords3,425,828
About this breach
A database containing roughly 3.4 million email addresses and passwords tied to the online game-retail site 2Games.com has been indexed by the investigation team. According to the team's catalog, the listing covers 3,425,967 records, nearly all of them paired with a password, and estimates the attack occurred around January 1, 2020. The listing is not attributed to any claiming actor, and the underlying incident has never been officially verified. Leak aggregators that track the same dataset describe it as surfacing on a public hacking forum, and one such listing, mirrored on Leaked.Domains, dates the material to 2018 and labels the hack unverified because the company never acknowledged it.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords. The catalog counts 3,425,967 email addresses and 3,425,828 passwords among the records, meaning nearly every entry includes both an email and an associated password.
The dataset appears to be account credentials rather than broader personal records. No names, payment details, addresses, or other identity information are listed in the indexed fields. Because the data circulated on hacking forums, it is possible copies exist elsewhere, but the full scope of what was shared cannot be confirmed from available records.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Email and password combinations are the raw material for several common attacks:
Credential stuffing. Attackers feed leaked email and password pairs into login forms at other websites. Because many people reuse passwords across services, a working pair from 2Games.com may also unlock email, social media, shopping, or banking accounts.
Account takeover. Anyone who still uses the same credentials on 2Games.com or any other site faces direct account compromise.
Phishing. With a valid email address in hand, scammers can send convincing messages that reference gaming purchases or account problems to trick recipients into revealing more information.
Further resale. Credential lists are commonly repackaged and sold, so exposure can persist long after the original leak.
The risks here center on account access rather than identity theft, since the indexed data does not include government identifiers or financial information. Still, a compromised email account can be used to reset passwords at many other services, which makes reuse the biggest danger.
What Should You Do If You Were Affected?
If your email address appears in this breach, take these steps:
Change your password everywhere you reused it, starting with your email account. Prioritize banking, shopping, and any account tied to that email address.
Create a unique password for each service. A password manager can generate and store distinct passwords so you do not have to memorize them.
Turn on two-factor authentication wherever it is offered, especially for email. Even if a password leaks, a second factor blocks most takeover attempts.
Watch for phishing. Be cautious with unexpected emails about gaming accounts, order problems, or payment issues, and never enter credentials through links in unsolicited messages.
Check whether you appear in this or related breaches by searching your email address, and review recent login activity on accounts you suspect may be affected.
Because the underlying incident is unverified and the records may be several years old, acting on the assumption that your credentials are exposed is the safer course. Older leaks remain useful to attackers precisely because many people never change affected passwords.
