---
title: "SCUF Gaming customer-account data incident"
description: "Evidence-backed account of SCUF Gaming customer-account data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/scuf-gaming-customer-account-data-incident-2015"
markdown_url: "https://www.ally.security/incidents/scuf-gaming-customer-account-data-incident-2015.md"
stix_url: "https://www.ally.security/incidents/scuf-gaming-customer-account-data-incident-2015/stix.json"
---

# SCUF Gaming customer-account data incident

A contemporaneously reported SCUF Gaming website compromise and customer incident notification associated by HIBP with a later-verified account-data corpus. A verified HIBP corpus associated with the June 2015 SCUF Gaming incident.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

A contemporaneously reported [SCUF Gaming](https://www.scufgaming.com/) website compromise and customer incident notification associated by HIBP with a later-verified account-data corpus. [2](#source-2)

## Impact

A verified HIBP corpus associated with the June 2015 SCUF Gaming incident. [2](#source-2)

Documented data types include:

- IP addresses — IP addresses listed in HIBP's DataClasses. [1](#source-1)
- Account credentials — Password hashes listed by HIBP; the available source does not specify the hashing algorithm, salt use, or crack status. [1](#source-1)
- Names — Display names listed in HIBP's DataClasses. [1](#source-1)
- Usernames and account identifiers — Usernames listed in HIBP's DataClasses. [1](#source-1)
- Contact information — Email addresses listed in HIBP's DataClasses. [1](#source-1)

A cited record reports 128,683 records (Unique email addresses represented in HIBP's verified corpus; not a count of confirmed people, customers, accounts, or total database rows; as of 2026-03-26). [1](#source-1)

## Timeline

### June 4, 2015 — Public disclosure

Latest date of customer incident-email reports embedded in Malwarebytes' June 8 contemporaneous article; the original SCUF notice publication time is not preserved as a first-party page. [2](#source-2)

### June 5, 2015 — Documented event

HIBP BreachDate for the associated corpus; contemporaneous reporting described public website-compromise reports on June 2 and customer incident-email reports by June 4, so this is not asserted as an exact intrusion timestamp. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Malwarebytes reported that SCUF Gaming's website had been compromised and that customers received a incident email. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

HIBP marked the SCUF Gaming incident record verified and not fabricated. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/scuf-gaming-customer-account-data-incident-2015/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Scuf Gaming breach record

advisory · Have I Been Pwned · Mar 26, 2026

<https://haveibeenpwned.com/api/v3/breach/ScufGaming>

<a id="source-2"></a>

### Up, Down, Left, Right, Hack

news · Malwarebytes Labs · Jun 8, 2015

<https://www.malwarebytes.com/blog/news/2015/06/up-down-left-right-hack>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Disclosed At · 90% confidence · current**  
   June 2015 SCUF Gaming website and customer-data incident: 2015-06-04
2. **Occurred At · 85% confidence · current**  
   June 2015 SCUF Gaming website and customer-data incident: 2015-06-05
3. **Affected Organization · 100% confidence · current**  
   June 2015 SCUF Gaming website and customer-data incident: SCUF Gaming
4. **Resulted In · 85% confidence · current**  
   June 2015 SCUF Gaming website and customer-data incident: SCUF Gaming account-data corpus
5. **Exposed Record Count · 100% confidence · current**  
   SCUF Gaming account-data corpus: 128,683 record
6. **Exposed Data Category · 100% confidence · current**  
   SCUF Gaming account-data corpus: IP addresses
7. **Exposed Data Category · 95% confidence · current**  
   SCUF Gaming account-data corpus: Account credentials
8. **Exposed Data Category · 100% confidence · current**  
   SCUF Gaming account-data corpus: Names
9. **Resulted In · 90% confidence · current**  
   June 2015 SCUF Gaming website and customer-data incident: Malwarebytes reported that SCUF Gaming's website had been compromised and that customers received a breach email.
10. **Exposed Data Category · 100% confidence · current**  
   SCUF Gaming account-data corpus: Usernames and account identifiers
11. **Exposed Data Category · 100% confidence · current**  
   SCUF Gaming account-data corpus: Contact information
12. **Resulted In · 100% confidence · current**  
   SCUF Gaming account-data corpus: HIBP marked the SCUF Gaming breach record verified and not fabricated.

</details>
