Data breach
flashrevolution.com
- Records
- 1,546,923
- Breach date
- 1 January 2020Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses1,546,923
- Passwords1,546,310
About this breach
The investigation team has indexed a data set tied to flashrevolution.com containing records for approximately 1.55 million accounts. According to the team's catalog, the listing holds 1,546,923 rows, each with an email address, and 1,546,310 records that also include a password. The team estimates the attack date as January 1, 2020, though that date is an estimate rather than a confirmed day of intrusion. The listing was added to the catalog on December 1, 2024, and no individual or group has claimed responsibility.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Public context around the name is complicated. Independent leak-indexing service Dark Eye lists a file called FlashRevolution.com.zip circulating alongside broad compilation archives such as Collection#3, which suggests the data may have spread through credential collections rather than a single documented hack. Separately, the rhythm game community Flash Flash Revolution, whose site name is similar, reported major breaches in 2016 and 2019 affecting millions of accounts, as covered by Mallory and DeHashed.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses across all 1,546,923 rows, and passwords in 1,546,310 of those rows. The catalog does not specify whether the passwords were stored in plaintext or as hashes, nor does it list usernames, dates of birth, IP addresses, or other fields.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
An exposed email and password pair is most dangerous when the same password protects other accounts. Attackers routinely test leaked credentials against banking, shopping, and social media logins, a technique known as credential stuffing. Because password reuse remains common, a single leaked password can unlock multiple accounts.
Email addresses alone also carry risk. They can feed targeted phishing messages that appear more convincing because they reference real services. If a leaked password also protects a primary email inbox, an attacker could intercept password resets for other services.
What Should You Do If You Were Affected?
Change the password for any account tied to flashrevolution.com, and change it anywhere else you reused that password.
Use a unique password for each account. A password manager can generate and store them.
Turn on two-factor authentication where it is offered, especially for email and financial accounts.
Watch for phishing emails that reference gaming accounts, forums, or account verification. Do not click links in unexpected messages; type site addresses directly.
In the news
- Dark Eye: FlashRevolution.com.zip leak listingcrawler.darkeye.io (opens in a new tab)
- Mallory: Flash Flash Revolution account compromisesmallory.ai (opens in a new tab)
- DeHashed: Flash Flash Revolution 2019 breach insightsdehashed.com (opens in a new tab)
- Mozilla Monitor: Flash Flash Revolution breach detailsmonitor.mozilla.org (opens in a new tab)
