A threat actor has published a database allegedly stolen from PokemonGym.nl, claiming the leak exposes approximately 19,600 accounts belonging to players of the browser-based Pokémon role-playing game.
The purported database contains account credentials, email addresses, IP addresses, profile information, gameplay statistics, and private messages exchanged between users. The actor released the data publicly rather than advertising it for sale.
Account data and private messages exposed
PokemonGym.nl describes itself as an online Pokémon RPG serving players in the Netherlands and other international markets. Users can create an account, select a starter character, capture and train Pokémon, battle other players, trade virtual assets, and communicate through the platform.
According to the forum listing, the allegedly compromised database contains 19,600 unique user records. The exposed fields purportedly include:
- Usernames and email addresses
- Argon2id password hashes
- Current and previous IP addresses
- Account creation and activity timestamps
- Age, gender, country, and account role
- Membership and account restriction details
- In-game balances, rankings, and progression data
- Battle, race, and gameplay statistics
- Private messages between players
The listing includes samples presented as recent account records alongside a separate table containing user-to-user messages. BreachNews is not reproducing the samples because they contain personal information and private communications.
While much of the dataset consists of game-related information, the combination of email addresses, IP addresses, profile attributes, and message history could create meaningful privacy and security risks for affected players.
Passwords protected with Argon2id
The sample records show passwords stored as Argon2id hashes using individual salts. Argon2id is a modern password-hashing algorithm designed to make large-scale cracking attempts computationally expensive.
Hashed passwords are not the same as plaintext credentials, but their exposure still creates risk, particularly for accounts protected by weak or commonly used passwords. A successful cracking attempt could also affect unrelated services when users reuse the same password across multiple websites.
Players should change their PokemonGym.nl passwords and update credentials on any other accounts where the same or a similar password was used. Unique passwords and a password manager can reduce the impact of credential reuse following a data leak.
Private communications increase the impact
The alleged inclusion of private messages makes the incident more sensitive than a conventional account database exposure. Message histories can reveal personal conversations, relationships between accounts, trading activity, and information users did not expect to become public.
The sample also appears to include school-linked email addresses, suggesting that some affected accounts may belong to younger users. BreachNews has not determined the age distribution of the alleged dataset or independently confirmed how many minors may be affected.
Exposed contact details and knowledge of a player’s activity could be used to create targeted phishing messages, impersonate platform administrators, or trick users with fraudulent offers involving their accounts or in-game assets.
Established actor adds weight to the claim
The threat actor behind the post has an extensive history of publishing alleged breach data and was previously associated with the Accenture incident acknowledged by the company. That history makes the PokemonGym.nl claim noteworthy, but it does not independently prove that every record is authentic or that the claimed total is accurate.
The structure of the published samples appears consistent with an application database used by an online role-playing game. The records contain interconnected account identifiers, authentication data, game progression fields, timestamps, and internal messaging tables rather than a simple marketing or mailing list.
The actor did not explain how access was obtained, when the intrusion occurred, or whether a vulnerability, compromised account, or exposed administrative system was involved.
PokemonGym.nl responds to BreachNews
Following publication, PokemonGym.nl told BreachNews it was “not aware of this incident” and said the exposed data “appears to be an old database.” The operator also requested information about where the data had been posted so it could investigate further.
BreachNews has since provided that information and will update this article if PokemonGym.nl shares additional details about the age or origin of the dataset.











