Data breach
CheapAssGamer.com
- Records
- 337,558
- Breach date
- 1 July 2015Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses337,558
- Passwords337,145
- UsernamesReported, not counted
- IP addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Our investigation team estimates that the gaming deal forum CheapAssGamer.com suffered a data breach around July 1, 2015. The incident targeted the site's forum, which ran on the IP.Board platform, and resulted in a database of user account information later surfacing in circulation. The listing contains 337,558 rows, of which 337,145 include passwords and all 337,558 include email addresses. No individual or group has claimed responsibility for the breach.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses, present for all 337,558 records in the listing
Passwords, present for 337,145 records
Independent breach databases, including the one maintained by Mozilla Monitor, also associate this incident with usernames and IP addresses, suggesting the exposed database held account profile details in addition to login credentials. The compromised passwords were reportedly stored as salted MD5 hashes, a hashing method now considered weak by modern standards.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Email addresses and passwords are the core building blocks of account takeover attempts. Even a decade after the breach, the main risks remain practical:
Password reuse. Anyone who used the same password on CheapAssGamer.com and other services, such as email, banking, or shopping accounts, may find those accounts vulnerable. Attackers routinely test leaked password and email pairs against popular sites, a technique known as credential stuffing.
Phishing. With a valid email address tied to a gaming community, attackers can craft convincing messages about account security or deal alerts to trick recipients into surrendering more information.
Weak hashing. Salted MD5 hashes can be cracked relatively quickly with modern hardware, meaning the original passwords behind the records may be recoverable by motivated attackers.
Because the breach is old, some affected users may have already moved on or changed passwords elsewhere without realizing this exposure existed.
What Should You Do If You Were Affected?
If you had an account on CheapAssGamer.com, or you frequently used the site around 2015, take these steps:
Change your password on CheapAssGamer.com if you still have an account there.
Update any other account where you reused the same or a similar password. Start with your primary email account, since it can be used to reset access to nearly everything else.
Enable two-factor authentication wherever it is offered, especially on email, banking, and shopping accounts.
Stay alert to phishing. Treat unexpected emails about account security or password resets with suspicion, and navigate to websites directly rather than through emailed links.
