Atlas Menu Cheat Service Breached: 64k Accounts Exposed

Atlas Menu Cheat Service Breached: 64k Accounts Exposed

Have I Been Pwned reports that the Atlas Menu cheat service, catering to GTA V and CS2 players, suffered a data breach in May 2026. An attacker reportedly gained full access to Atlas systems and subsequently published the service’s database to a public GitHub repository. This isn’t just a minor leak; it’s a full data dump.

The incident exposed approximately 64,000 unique email addresses, alongside usernames, IP addresses, support tickets, and passwords. Crucially, while the passwords were stored as bcrypt hashes, the exposure of email addresses and associated data still poses a significant risk. Even strong hashing doesn’t completely negate the danger when other identifying information is public.

This breach highlights the inherent risks of using any online service, even those operating in gray areas. For defenders, it’s a reminder that user data, regardless of the service’s legitimacy, can and will be targeted. The attacker’s calculus here was simple: find a vulnerable, less-defended target with valuable user data and exploit it.

What This Means For You

  • If you or anyone in your organization used the Atlas Menu service, assume your credentials are compromised. Check if any of the exposed email addresses are linked to corporate accounts. Force password resets on any services where you might have reused these credentials. Don't underestimate the risk of credential stuffing, even from 'non-critical' services.

🛡️ Detection Rules

3 rules · 6 SIEM formats

3 detection rules auto-generated for this incident, mapped to MITRE ATT&CK. Sigma YAML is free — export to any SIEM format via the Intel Bot.

critical T1048 Exfiltration

Atlas Menu Data Breach - Public GitHub Repository Exposure

Sigma YAML — free preview

Source: Shimi's Cyber World · License & reuse

✓ Sigma · Splunk SPL Sentinel KQL Elastic QRadar AQL Wazuh Get rules for your SIEM →
Take action on this incident
🔍 Threat intel on Atlas Menu All breaches, IOCs & vendor exposure

Related coverage on Atlas Menu

Microsoft Slams Zero-Day Public Disclosure as Researcher Promises More

Microsoft has publicly condemned the practice of releasing zero-day vulnerabilities with working proof-of-concept code, deeming it "never justifiable." The tech giant's stance comes as a...

threat-inteldata-breachgovernmentvulnerabilitymicrosofttools
/SCW Vulnerability Desk /HIGH /⚑ 1 IOC /⚙ 3 Sigma

Ajax Football Club Cyber Breach Leads to Arrest in Netherlands

Dutch law enforcement has arrested a suspect in Buren, Netherlands, in connection with a cyber breach targeting the prominent Ajax football club. The operation, detailed...

threat-inteldata-breachgovernmentmicrosofttools
/SCW Research /MEDIUM /⚙ 3 Sigma

Windows 11 KB5089573 Update: Performance Fixes Released

Microsoft has rolled out the KB5089573 preview cumulative update for Windows 11 versions 25H2 and 24H2. According to BleepingComputer, this update includes 30 changes, primarily...

threat-inteldata-breachmalwaremicrosofttools
/SCW Research /MEDIUM