Skip to content

EVA VR Arena Data Allegedly Leaked, 20,000 Customers Exposed and €1M in Gift Cards Generated

Breach Report France flagFrance Leisure / VR Entertainment Free Download

EVA VR Arena Data Allegedly Leaked, 20,000 Customers Exposed and €1M in Gift Cards Generated

A forum user posting as 4me44 has published what they describe as customer data from a French location of EVA, an operator of competitive virtual reality battle arenas. The release covers 20,274 records containing names, usernames, email addresses, dates of birth, phone numbers, and full home addresses. More significant than the records is what the actor claims alongside them: administrative access to the operator's back office, demonstrated by generating a campaign of 1,000 gift cards worth €1,000,000 and publishing working voucher codes. The actor also claims access to money transfer and reservation functions. The claim is unverified.

Records20,274
Vouchers created€1,000,000
PriceFree
Actor4me44

Post details

TargetEVA, Nantes Sud location
CountryFrance flagFrance
SectorLeisure / VR entertainment
ListingFree, reply or upgrade
Records20,274 lines
Also claimedBack office admin access
Observed
Actor4me44

!Allegedly included

  • Full names
  • Email addresses
  • Usernames and display names
  • Dates of birth
  • Gender
  • Phone numbers
  • Street addresses
  • Cities and postal codes
  • Newsletter preferences
  • Membership expiry dates
  • Gift card campaign function
  • Money transfer function
  • Reservation records
  • Vendor records

Screenshots

Potential impact

The customer records carry no passwords or payment details, but name, date of birth, home address and phone together remain a workable identity and social engineering set. The more urgent element is the claimed write access to the operator's voucher system. Generating redeemable value inside a live back office is not data theft, it is direct financial fraud against the business, and any codes issued remain valid until the operator identifies and voids them. The same access, if genuine, would also reach the money transfer and reservation functions the actor lists. Because the release covers a single venue while a separate actor is said to hold the national dataset, the wider customer base may be exposed independently.

iStatus

Unverified

A record sample is published and the field structure is consistent with a platform export. Dark Web Informer is not reproducing the voucher codes, which are live financial instruments, nor the download location. The actor states a different group already published a dataset covering all locations, and describes their own release as a partial extract with substantial overlap. The account is recent with no standing. Nothing has been independently corroborated. The claim is unverified and EVA has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest