Data breach
gamecom.com
- Records
- 1,004,581
- Breach date
- 1 January 2020Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses1,004,581
- Passwords1,004,408
About this breach
Our investigation team has indexed a data set connected to the domain gamecom.com containing roughly 1 million user records. The team estimates the breach occurred on or around January 1, 2020, and the listing was added to our database on December 1, 2024. The data set holds 1,004,581 rows, and no individual or group has publicly claimed responsibility for it.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses: 1,004,581 records, meaning essentially every row in the data set includes one.
Passwords: 1,004,408 records, meaning almost every entry also contains a password.
Because the records pair email addresses with passwords, the exposure is consistent with leaked account credentials rather than basic contact information alone. We cannot determine from the indexed fields whether the passwords were stored in plaintext or in a hashed form, and we cannot verify additional data types beyond those listed here as of September 25, 2026.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
An email and password pair is exactly what attackers need to attempt an account takeover. The main risks include:
Credential stuffing. Many people reuse the same password across sites. If you used this password anywhere else, criminals can run it against banking, email, shopping, and gaming accounts until one opens.
Account takeover. Anything tied to your email address, from password resets to two-factor codes, can be intercepted if someone gains access to your inbox.
Phishing. Attackers who confirm your email is real and active can send targeted messages designed to extract more information or install malware.
Follow-up fraud. Leaked credentials circulate on dark web markets for years. A 2020 leak can still power attacks long after the original incident fades from public attention.
What Should You Do If You Were Affected?
If your email address appears in this breach, take these steps:
Change your password on gamecom.com, if you had an account there, and on any other site where you reused the same password.
Use unique passwords for each account. A password manager can generate and store strong, distinct passwords for every service you use.
Turn on two-factor authentication wherever it is offered, starting with your primary email account.
Watch for phishing. Be skeptical of unexpected emails referencing your account, your password, or a security incident, and never enter credentials through links in unsolicited messages.
Review account activity. Check unfamiliar logins, password-reset notices, or messages you did not send, which can signal that someone already has access.
