According to German media reports, a list of 1800 Minecraft usernames and passwords has been published online – potentially allowing anyone to break into your account and cause mayhem in the popular chunky 3D world.
Heise reports that many of the affected accounts appear to be belong to German gamers, and that some of the login credentials have been verified to be valid.
If unauthorised users exploited the exposed email addresses and passwords they could not only log into other people’s gameworlds, but also download a full version of the game which normally sells for 19.95 Euros ($26.95 or £17.95)
Quite how criminals managed to steal the credentials for so many Minecraft users isn’t clear. Possibilities range from simple phishing attacks, keylogging malware stealing players’ details as they log into the game, or even a security breach at Minecraft itself. (Let’s hope it’s not the last one – because the game has over 100 million registered users).
And although some 1800+ usernames and passwords have been published online, there’s no guarantee that whoever gained access to them hasn’t got a whole lot more in their back pocket which they haven’t chosen to release to the rest of the world.
There is no mention of the security breach on Minecraft’s homepage, but my recommendation would be that if users have any concern that their accounts might be exposed to hackers that they should change their passwords immediately. It goes without saying that they should be particularly concerned if they are using the same password anywhere else on the web.
Even if you aren’t worried about a stranger accessing your Minecraft account, you should be aware of the dangers that once criminals know you play Minecraft and have your email address they could easily spam out attacks which use social engineering to trick you into clicking on dangerous links or open malicious attachments.
Mojang, the makers of Minecraft who were acquired by Microsoft for an eyewatering $2.5 billion last November, has published advice on how players can choose a more secure password here.
Of course, there is nothing they can do to ensure that you are not using the same password elsewhere on the net – there are some things you need to manage for yourself if you value your privacy and security online.
[…] A list of 1800 Minecraft usernames and passwords has been published online – potentially allowing anyone to break into your account and cause mayhem in the popular chunky 3D world. Read more in my article on the Hot for Security blog. …read more […]
[…] 1800+ Minecraft usernames and passwords leak online […]
[…] expert Graham Cluley speculates the cause could have been the result of “simple phishing attacks, keylogging malware stealing […]
[…] expert Graham Cluley speculates the cause could have been the result of “simple phishing attacks, keylogging malware stealing […]
[…] via: Hot For Security […]
This is nothing buddy. There is 50k+ accounts leaked. Its mainly don’t by brute force and is super simple. Its down to people using stupid account passwords like “password” or “minecraft”.
This is a very small leak in comparison.
Oh and a small example: http://imgur.com/9kPSSgV
Took me 15 min tops to get these.
would you be able to reply with an account because i have no clue where or how to get them :)
Most of the passwords shown here suggest Minecraft users don’t just LOOK like blockheads ;~ )
Hello Graham Cluley like annon said there is 50k + accounts out there and most or even half are used for bad stuff but many of the unmigrated accounts are PUT out there so less fortunate people can use them and enjoy themselves
[…] lista con 1800 nombres de usuarios y contraseñas válidas de Minecraft fueron publicados en Pastebin. No hay ninguna pista de dónde sacaron las credenciales, o si hay alguna probabilidad que filtren […]
[…] Graham Cluely points out in his post on the leak, Microsoft hasn’t posted news of a security breach on the Minecraft site. Based on similar […]
[…] is not known how the hackers got their hands on the credentials, but security analyst Graham Cluely wrote on the Hot for Security blog: ‘Possibilities range from simple phishing attacks, keylogging […]
[…] Graham Cluely points out in his post on the leak, Microsoft hasn’t posted news of a security breach on the Minecraft site. Based on similar dumps […]
[…] Cluely is rámutatott a szivárgásról Ãrt posztjában, a Microsoft egyelÅ‘re nem Ãr sehol a Minecraft weboldal biztonságának megsértésérÅ‘l. Ennek […]
[…] Cluley, investigador especializado en seguridad informática ha explicado en Hot for Security que: “No puedo decir cómo se ha producido esta filtración. Las posibilidades van desde […]
[…] Cluely is rámutatott a szivárgásról Ãrt posztjában, a Microsoft egyelÅ‘re nem Ãr sehol aMinecraft weboldal biztonságának megsértésérÅ‘l. Ennek […]
[…] is not known how the hackers got their hands on the credentials, but security analyst Graham Cluely wrote on the Hot for Security blog: ‘Possibilities range from simple phishing attacks, keylogging […]
[…] According to security researcher Graham Cluley: […]
[…] more in their back pocket which they haven’t chosen to release to the rest of the world,” wrote Graham […]
exactly
[…] more in their back pocket which they haven’t chosen to release to the rest of the world,” wrote Graham […]