Last week two separate sellers on cybercrime forums offered what they claimed were millions of Minecraft player records. One listed 18 million, another 9 million. Samples included usernames, email addresses, and password hashes. It sounded bad.
Researchers obtained and examined the samples. They discovered the 1,000-record test set came from only three different Minecraft servers. Many entries repeated. There were no timestamps proving the data was recent. The pattern matches infostealer malware that has targeted Minecraft players for years, not a direct compromise of Mojang or Microsoft systems.
What players should actually do
- Change your Microsoft account password if it matches anything used on third-party Minecraft servers.
- Enable two-factor authentication on your Microsoft account immediately.
- Stop downloading random mods, clients, or cheats from untrusted sources.
- Use unique passwords for your Minecraft-related accounts.
Previous malware campaigns in 2025 and 2026 specifically targeted Minecraft users with infostealers that grab launcher credentials, browser data, and saved passwords. The current listings appear to be the downstream result of that ongoing problem rather than a new headline-grabbing hack.
It is unclear how old the dataset is, since there are no timestamps.
That quote comes from the researchers who reviewed the seller samples. The limited scope and repetition strongly suggest the data was scraped from a handful of compromised community servers, not pulled from any central Mojang authentication system.
Minecraft itself has not issued an official statement on these specific listings. That is consistent with the findings that this is not their infrastructure that was breached. Still, the incident is a useful reminder that the multiplayer ecosystem is only as secure as the weakest server and the laziest player habits.
News





