Data breach
MCResolver
- Records
- 13,080,236
- Breach date
- 1 January 2015Estimated
- Added
- 4 February 2025
What was exposed
2 types of data
- IP addresses13,080,236
- Usernames13,080,236
About this breach
MCResolver, an IP resolver service popular in the Minecraft community, suffered a data breach that exposed 13,080,236 rows of records, according to the investigation team. Each row paired a Minecraft nickname with the IP address that had been linked to it through the service. Our investigation team estimates the breach occurred around January 1, 2015. Secondary trackers, including DeHashed, describe the leak surfacing in December 2015, so the exact timing remains uncertain. The dataset circulated after the incident, putting the connection details of a large number of players into wider distribution.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach: IP addresses and Minecraft nicknames, with 13,080,236 records for each data type.
Not every individual is affected by every type of data listed here.
The records do not include passwords, email addresses, or payment information, according to available descriptions of the dataset. However, the pairing of a username with an IP address is itself sensitive. It connects an online identity to a real-world network connection, which was the core purpose of the resolver service.
What Are the Potential Risks for Affected Individuals?
The main risks here differ from those in typical account breaches, because the leaked data contains no credentials:
Targeted DDoS attacks. With an IP address, an attacker can attempt to flood a home connection with traffic. This kind of attack was common in the Minecraft community at the time, particularly around competitive servers.
Doxxing. An IP address can reveal an internet provider and an approximate location, which people have used to link anonymous usernames to real identities.
Correlation with other leaks. A nickname paired with an IP address can help tie accounts across platforms together when combined with other leaked datasets.
Phishing and social engineering. Attackers who know a player's username and rough details can craft more convincing messages, for example posing as server staff.
Because IP addresses change over time, some of the addresses in this dataset may no longer point to the affected households. The nickname data, however, remains useful to anyone building profiles of players.
What Should You Do If You Were Affected?
If you believe your Minecraft username or IP address was in this dataset, consider these steps:
Check whether you appear in the breach.
Use a VPN if DDoS is a concern. A VPN masks your real IP address during online gaming, making targeted attacks harder.
Restart your router. Many home internet providers assign dynamic IP addresses, so a restart can change yours if it appeared in the leak.
Secure your Minecraft account. Even though no passwords appeared in this dataset, enable two-factor authentication where available and use a unique password you do not reuse elsewhere.
Watch for phishing. Be cautious with messages referencing your username or claiming to come from Minecraft server staff.
