CSIDB logo
Incident

Game24h.vn

Incident posture

Attack window
Oct 2020
Location
Viet Nam
Status
Historical
CIA posture
Available to members
Updated
2025-10-28 00:00

Linked entities

Victim
Game24h.vn
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A threat actor advertised the sale of stolen user databases from seventeen companies, including Game24h.vn, on a hacker forum, aggregating approximately 34 million records. The broker claimed no direct involvement in the breaches but offered datasets containing emails and variably hashed passwords, with the victim's data exposed via MD5 hashing. Other impacted entities spanned e-commerce, education, and entertainment sectors, with some datasets also including names, contact details, financial information, or national identifiers. While one company acknowledged the breach, most had not publicly confirmed compromises at the time of reporting. The broker historically sold similar datasets privately before potential public releases.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On October 28, 2020, a threat actor advertised the sale of stolen user databases from seventeen companies on a hacker forum, including Game24h.vn. The seller, operating as a data breach broker rather than the original attacker, claimed no direct involvement in compromising the companies but facilitated the sale of aggregated records totaling approximately 34 million users across all affected organizations. The Game24h.vn breach exposed user email addresses paired with passwords hashed using the MD5 algorithm, though the exact number of compromised accounts from this specific platform was not disclosed in the broker's listing. Other prominent victims included Geekie.com.br (8.1 million records), Clip.mx (4.7 million), and Wongnai.com (4.3 million). The broker indicated that stolen databases typically undergo private sales with prices ranging from $500 to $100,000 before eventual public release on forums.

The incident exposed significant quantities of sensitive information across multiple platforms, with Game24h.vn users facing credential compromise risks due to the weak MD5 hashing method protecting passwords. While Singaporean grocery service RedMart confirmed its breach, most affected companies—including Game24h.vn—had not publicly acknowledged compromises as of the article's October 31, 2020 publication date. Exposed data types varied by organization, with some breaches including financial details, government identifiers like CPF numbers, and social media tokens. Security analysts emphasized the heightened risk of credential stuffing attacks due to password reuse across services. No containment measures or victim notifications specific to Game24h.vn were documented in the source material, though broader security recommendations centered on credential management practices for impacted user populations.

Sources

Sources available to members: 1 source.

CSIDB