SCUF Gaming customer-account data incident

A contemporaneously reported SCUF Gaming website compromise and customer incident notification associated by HIBP with a later-verified account-data corpus. A verified HIBP corpus associated with the June 2015 SCUF Gaming incident.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

A contemporaneously reported SCUF Gaming website compromise and customer incident notification associated by HIBP with a later-verified account-data corpus. [2]

Impact

A verified HIBP corpus associated with the June 2015 SCUF Gaming incident. [2]

Documented data types include:

  • IP addresses — IP addresses listed in HIBP’s DataClasses. [1]
  • Account credentials — Password hashes listed by HIBP; the available source does not specify the hashing algorithm, salt use, or crack status. [1]
  • Names — Display names listed in HIBP’s DataClasses. [1]
  • Usernames and account identifiers — Usernames listed in HIBP’s DataClasses. [1]
  • Contact information — Email addresses listed in HIBP’s DataClasses. [1]

A cited record reports 128,683 records (Unique email addresses represented in HIBP’s verified corpus; not a count of confirmed people, customers, accounts, or total database rows; as of 2026-03-26). [1]

Timeline

  1. Public disclosure

    Latest date of customer incident-email reports embedded in Malwarebytes’ June 8 contemporaneous article; the original SCUF notice publication time is not preserved as a first-party page.

    [2]
  2. Documented event

    HIBP BreachDate for the associated corpus; contemporaneous reporting described public website-compromise reports on June 2 and customer incident-email reports by June 4, so this is not asserted as an exact intrusion timestamp.

    [1]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Malwarebytes reported that SCUF Gaming’s website had been compromised and that customers received a incident email. [2]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

HIBP marked the SCUF Gaming incident record verified and not fabricated. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]