Sellers are advertising alleged Minecraft player data, but the evidence does not establish a breach of Mojang or Microsoft. Cybernews reports claims of 9 million and 18 million records. Its researchers found the same 1,000-record sample behind both listings, containing usernames, email addresses and some password hashes. The data's age, origin and full scale remain uncertain.
That is the position in the reporting reviewed on 11 October 2026. Players can take sensible precautions without treating a seller's claim as a confirmed victim count.
Start with the accounts you can protect
A headline cannot tell you whether your own account is affected. A more useful starting point is to check whether you reuse a gaming password for email or another service.
Microsoft's password guidance advises against using the same or a similar password on different websites. If one service exposes it, an attacker may try it elsewhere. This is known as credential stuffing: testing stolen login details against other accounts.
For example, imagine a player using the same password for a community forum and their email. A stolen forum password could give an attacker a way into the email account. This is a hypothetical example, not an account of what happened in this case.
Use a unique password wherever you still need one. Start with email, because it is often where you receive password-reset messages for other accounts. A password manager can help you avoid having to remember every password.
Treat mods as software you are installing
There is a separate, documented reason to take gaming downloads seriously. On 18 June 2025, Check Point Research described malicious GitHub repositories posing as Minecraft mods and tools. The downloads led to malware designed to steal information. That research does not establish where the records now being advertised came from.
A mod changes or adds features to a game, but it also runs code. An infostealer is malicious software that collects information from a device; our guide to password stealers explains the risk in more detail.
Before installing a mod, check that the download comes from the project's established publisher or distribution page. A link in a chat message, a familiar name or a popularity counter is not enough to verify a file. If installation instructions ask you to switch off security protection, stop and check the source independently.
If you suspect someone has accessed your account
Respond to evidence such as unfamiliar account activity or a suspicious download you actually ran. You do not need to wait for a public breach announcement.
- Check the device. Microsoft's recovery guidance recommends a full malware scan before changing your password on the PC. If you need urgent help with an account, use a device you trust.
- Secure the affected account. Follow the provider's recovery process, change exposed or reused passwords, and check account settings for changes you did not make. For email, include forwarding rules.
- Strengthen future sign-ins. Microsoft recommends passwordless options, including its Authenticator app and security keys. Keep recovery contact details current, too.
Open the provider's site yourself when checking an alert. An unsolicited message offering to recover a gaming account should not become your route to the sign-in page.
When a gaming incident could affect work
If you used a work password on a gaming service, or ran a suspicious download on a device used for work, tell your IT team. Explain which account or device was involved and what you noticed. They need those details to decide what to investigate.
For everyone else, begin with one concrete check: make sure your email account does not share its password with a gaming account. That is a useful change you can make while the claims remain unresolved.




