Skip to content

Drag the artwork to explore. Use the arrow keys when it is focused.

Security & ExploitsMinecraft Malware

18 Million Minecraft Player Records Allegedly Sold on Cybercrime Forums

Researchers examined samples containing usernames, emails and password hashes from two dark web listings but say the data likely stems from infostealer malware targeting players rather than a direct Mojang breach.

3 min read

Minecraft players should check their email addresses and consider changing passwords after two cybercrime forum listings this week offered what sellers claim are millions of compromised accounts. One post advertises 18 million records while another lists 9 million. Cybernews acquired samples from both and found usernames, email addresses and password hashes.

Not a Mojang server breach

The data does not appear to come from a direct hack of Mojang or Microsoft infrastructure. Instead researchers believe it was harvested by infostealer malware that has been circulating among Minecraft players for years. A 2025 Check Point report already flagged Russian-linked malware specifically designed to infect Minecraft users often delivered through malicious mods or cracked launchers.

Diagram showing multistage attack using fake Minecraft mods from GitHub to deploy infostealer
Infection overview of the 2025 Russian-linked malware campaign targeting Minecraft players Source
The uncomfortable reality is that many Minecraft players still download random mods, texture packs and “free” clients from untrusted sources. Those are the real entry points here. Mojang cannot patch user stupidity.

Samples reviewed by Cybernews showed emails that already exist in multiple known combo lists on Have I Been Pwned. This strongly suggests the data was compiled from previous malware campaigns rather than a fresh break-in at Minecraft’s authentication systems. Passwords are stored as hashes which still require cracking but remain dangerous in volume.

  • Listings appeared on underground forums within the past few days
  • Data includes Minecraft usernames, associated emails and hashed passwords
  • Samples of 1,000 records were provided to researchers for verification
  • No evidence of full account tokens or payment information in the samples
  • Players using the same email-password combo across services remain at risk

This suggests that the data source may be infostealer malware.

The report serves as a timely reminder for the Minecraft community. With hundreds of millions of monthly players the game remains a lucrative target for malware distributors. Official advice from Mojang has long warned against third-party launchers and unverified mods. Those warnings continue to be ignored at scale.

What players should do right now

  • Check if your email appears in the breach at haveibeenpwned.com
  • Enable two-factor authentication on your Microsoft/Minecraft account if not already active
  • Stop downloading mods from random websites or Discord links
  • Use unique strong passwords for your Minecraft account
  • Monitor linked email accounts for suspicious login attempts

Mojang has not issued an official statement on the specific forum listings as of publication. The company routinely resets compromised accounts when patterns are detected but the volume claimed here would be difficult to address individually. The best defense remains on the player side.

Did you enjoy this story?