Data breach
cheat-master.net
- Records
- 2,024,227
- Breach date
- 1 January 2020Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses2,024,227
- Passwords2,023,104
About this breach
The investigation team has indexed a credential dump tied to cheat-master.net, a website associated with video game cheats, containing more than two million records. According to the team's catalog, the dataset holds 2,024,227 rows, including 2,024,227 email addresses and 2,023,104 passwords. The team estimates the breach occurred around January 1, 2020, and the listing was added to the database on December 1, 2024. No group has claimed responsibility for the leak, and no ransom demand or hacking claim is connected to it in the catalog.
The breach was indexed independently by the credential-search service Leak-Lookup, which lists cheat-master.net among its databases with roughly 2,027,759 records, a figure broadly consistent with the investigation team's count.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords.
The catalog does not indicate whether the passwords were stored in plain text or in hashed form, and no notice from the site's operators describes how they were protected. No names, payment details, phone numbers, or other personal identifiers are recorded in the indexed fields.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risk from an email-and-password dump is account takeover. Many people reuse the same password across multiple sites, so a single leaked credential pair can expose email accounts, social media profiles, shopping sites, and other services where the same combination was used.
Attackers commonly feed leaked lists into automated "credential stuffing" tools, which try the same email-and-password pairs against banks, streaming services, and other popular sites until something works. A working email account is particularly valuable because email password resets can then be used to hijack further accounts.
Even without password reuse, the exposure of an email address can invite targeted phishing: a message that appears to come from a legitimate service may ask the recipient to "verify" details or reset a password, harvesting fresh credentials.
What Should You Do If You Were Affected?
If you had an account on cheat-master.net, or think your credentials may be in this dataset, take these steps:
Change the password on any cheat-master.net account, and change it anywhere else you used the same password.
Secure your email account first. A unique, strong email password and two-factor authentication block the most damaging path attackers use after a breach.
Turn on two-factor authentication where available on other accounts, using an authenticator app rather than text messages when possible.
Use a password manager to generate and store distinct passwords for every service, so one leak cannot unlock others.
Watch for phishing. Treat unexpected password-reset emails or urgent "security" messages with suspicion, and never enter credentials through a link you did not initiate.
Check for reuse. If a password you used elsewhere matches what you used on this site, update it immediately.
Because the site's operators have not published a public notice about this incident in sources reviewed as of September 25, 2026, there is no official statement confirming which users are included or how the data was protected. Acting on your own behalf, as described above, remains the most reliable protection.
