Netherlands
Gaming / Online RPG
Point-Gated Download
PokemonGym.nl Database Allegedly Leaked, 19,600 Player Accounts and Private Messages Published
A forum user posting as 888 has published what they describe as the database of PokemonGym.nl, a Dutch online Pokémon RPG. The post claims the breach occurred in July 2026 and exposed 19,600 unique users. The advertised schema covers account, profile, and gameplay tables, including usernames, email addresses, two IP address fields, age, gender, country, and password hashes. Separately, the post includes a dump of the platform's private messaging table with the full text of user-to-user conversations. The password values shown are Argon2id hashes, a modern algorithm that substantially limits recovery. The data is offered behind a forum points paywall. The claim is unverified.
Netherlands▣Post details
Netherlands!Allegedly included
- Usernames
- Email addresses
- Argon2id password hashes
- Secondary password field
- IP addresses (two fields)
- Age
- Gender
- Country
- Private message content
- Sender & recipient IDs
- Message timestamps
- Account role & status
- Ban reasons & durations
- Premium & VIP expiry
- Activity & playtime metrics
- In-game currency balances
◱Screenshots
⚠Potential impact
The credential exposure here is milder than most gaming leaks. The hashes shown use Argon2id with high memory and iteration parameters, which is current best practice and means bulk password recovery is not realistically achievable; the immediate credential-stuffing risk is correspondingly low. That is worth stating plainly, because it is the part of this dataset that was handled well. The exposure that matters is elsewhere. The account table pairs email address and username with age, gender, country, and two IP addresses, and the dump extends to the platform's private message table including full message text. A fan-made Pokémon RPG draws a user base skewed heavily toward children and teenagers, and the sample conversations are consistent with that. Publishing the private correspondence of that population alongside the identifiers needed to locate and contact them is the central harm here, and it is not one the affected users can remediate: a password can be changed, a past conversation cannot be unpublished. The combination of approximate location from IP, self-reported age and gender, and an active messaging history is precisely the material that supports targeted approaches to minors, which places this well above the usual severity of a small gaming breach. The schema also lists a second credential field alongside the hashed one, whose contents and format are not evident from the post. The claim is unverified.
iStatus
UnverifiedThe post includes samples from both the user table and the private message table, and places the download behind a points paywall. Unlike the throwaway accounts behind many listings, this one is long-established on the forum with a substantial posting history and high standing, which speaks to the poster's position in that community rather than to the authenticity of the data. Neither the record count nor the dump has been independently corroborated. The claim is unverified and PokemonGym.nl has not publicly addressed it. Given the likely age profile of the user base, this is a case where prompt notification to players and their parents would matter more than usual, and players who reused their password elsewhere should change it regardless of the hashing strength.
DARK WEB INFORMER - THREAT INTELLIGENCE