Data breach
Coupon Mom / Armor Games
- Records
- 11,032,658
- Breach date
- 8 February 2014Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses11,032,658
- Passwords11,032,021
About this breach
In 2014, a file surfaced containing roughly 11 million email addresses and plain text passwords that allegedly came from Coupon Mom, a coupon and savings website, and Armor Games, a browser gaming platform. Our investigation team estimates the breach covers 11,032,658 records, with 11,032,021 passwords, and places the attack date at February 8, 2014. The origins of the file have never been conclusively proven. Both companies told regulators and researchers that the records did not match their full customer bases, and Armor Games said some people in the file reported never having used either site. The listing is therefore treated as an unverified compilation rather than a confirmed single-company hack, and it may draw on records from multiple sources that shared subscribers.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
February 8, 2014: The estimated date of the breach, as tracked in breach monitoring databases including Mozilla Monitor.
October 24, 2014: According to a notification Armor Games filed with the California Attorney General, the company discovered on this date that a third party had obtained users' emails and hashed passwords. It hired a security auditor, implemented recommended changes, and notified users.
October 24, 2017: Armor Games says a security researcher informed the company of a file containing emails and plain text passwords claiming to originate from Armor Games and Coupon Mom. The company began investigating whether it was the true source, noting the file held far fewer records than were breached on either system in 2013, and again notified and required password resets for affected users.
July 2020: Researchers determined the same file also contained BeerAdvocate accounts from a previously unknown breach, further complicating its origins.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (11,032,658 records) and passwords (11,032,021 records). The passwords in the circulated file were stored in plain text, meaning they were readable by anyone who obtained it.
Armor Games' notification to the California Attorney General states that the file contained no financial information, names, addresses, or game data.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main danger is password reuse. Because the file contains email and password pairs in readable form, anyone holding it can try those credentials against email providers, banking sites, social media, and shopping accounts. People who used the same password on Coupon Mom, Armor Games, or any other service are the most exposed.
Credential stuffing is a related risk: attackers feed large lists of leaked email and password pairs into login pages automatically, hoping a percentage of them still work. Even accounts at services that were never breached can be compromised this way.
The file can also support phishing. With a valid email address and a password a person has used elsewhere, a convincing message claiming an account issue is more likely to be trusted.
Because the file's true origins are unclear, it is reasonable to assume your email and a password you have used could be in it even if you never visited either site.
What Is Coupon Mom / Armor Games Doing in Response?
Armor Games' regulatory notice is the only confirmed operator response. In it, the company said it investigated the file's origin, treated the matter as a breach of its own users as a precaution, required affected users to change their passwords on its site, and recommended changing the same password anywhere else it was used. The company noted it had already hired a security auditor and implemented recommended changes after its 2014 discovery. Coupon Mom's response was not documented in the sources reviewed as of September 25, 2026.
What Should You Do If You Were Affected?
Change your password on Armor Games, Coupon Mom, and BeerAdvocate if you used any of them.
If you reused that password anywhere else, change it there too, starting with email and financial accounts. Email is the priority because password resets for other services often route through it.
Use a unique, strong password for every account, and consider a password manager to keep track of them.
Turn on two-factor authentication wherever it is offered.
Watch for phishing emails that reference these sites or cite a password you recognize as proof of legitimacy.
