Data breach
CrimeCraft MAYN Games
- Records
- 543,579
- Breach date
- 1 February 2021Estimated
- Added
- 24 March 2025
What was exposed
2 types of data · 3 more reported · 1 puts you at serious risk
- Email addresses543,579
- Passwords543,579
- UsernamesReported, not counted
- IP addressesReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In early 2021, CrimeCraft, an online multiplayer shooter operated by MAYN Games, appears to have suffered a data breach that exposed account records tied to the game's website. The listing was documented by the investigation team, which estimates the attack occurred around February 1, 2021, and indexes 543,579 records, each containing an email address and a password. No threat actor has publicly claimed responsibility in connection with this listing, and the team found no evidence of a company statement about the incident. Third-party breach trackers, including SynScan and LeakCheck, also cataloged the breach, with SynScan attributing the attack to an actor using the handle @donjuji and reporting a larger record count of roughly 1.57 million. The discrepancy in record counts between sources has not been reconciled.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords.
That is what the investigation team confirmed in the indexed records. Independent trackers describe a broader set of fields. SynScan reports the leak also contained usernames, IP addresses, and dates of birth, and says the passwords were stored as Ruby on Rails Restful-Auth SHA1 hashes, a format identified as hashcat mode 27200. LeakCheck similarly lists email addresses, usernames, passwords, dates of birth, geographic locations, and IP addresses among the exposed data. Neither tracker links to a notice from MAYN Games itself, so these additional fields could not be independently verified against a company source.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risk is account takeover. If a password you used on CrimeCraft or mayngames.com matches one in this leak, anyone holding the data can try it on your email, gaming, shopping, and social media accounts. This technique, called credential stuffing, works because people often reuse the same password across many sites.
SynScan reports that 91 percent of the hashed passwords in its copy of the dataset were cracked, which suggests many of the stored passwords were recoverable. Even if yours was not cracked, hashed passwords from older, weaker algorithms remain a target for attackers with time and computing power.
Exposed email addresses also invite phishing. Attackers who know you played a specific game can send convincing messages that reference the game or ask you to "verify" an account. If additional fields such as dates of birth or IP addresses were indeed included, that information can make phishing attempts more believable and help with identity-related fraud.
What Should You Do If You Were Affected?
If you had a CrimeCraft or MAYN Games account, take these steps:
Change the password you used on the site, and change it anywhere else you reused it. Each account should have a unique password.
Use a password manager to generate and store strong, distinct passwords.
Turn on two-factor authentication wherever it is offered, especially on your email account, which protects access to password resets for everything else.
Be cautious with emails referencing CrimeCraft, MAYN Games, or account security. Do not click links or enter credentials through unexpected messages.
Watch for unusual sign-in activity on accounts that shared a password with this one.
Because the breach is several years old, your data may already have circulated in credential dumps used for automated login attempts. Updating reused passwords still closes the most common path attackers use from old leaks to live accounts.
