Dark Web Intel: Pokémon Creed Hack Exposed 115,864 Passwords
HEROIC analysts identified the Pokémon Creed breach, a dataset tied to the domain pokemoncreed.net and dated August 8, 2014. Pokémon Creed was a Pokémon-themed RPG website that was hacked following a dispute with a rival site, Pokémon Dusk. A Facebook user identifying as "Cruz Dusk" claimed responsibility and shared the dumped MySQL database publicly. The breach exposed 115,864 records, including usernames, email addresses, plaintext passwords, and IP addresses.
Dark Web Intel: A Rivalry Turned Into a Mass Password Leak
This breach did not start as a quiet, profit-driven theft. It appears to have started as retaliation in a dispute between two fan communities, which makes it no less dangerous for the people caught in the middle. Because the passwords were stored and leaked in plaintext, every single one of the 115,864 accounts came with a working, ready-to-use password attached, no cracking or guessing required.
What Was Exposed in the Pokémon Creed Breach
- 115,864 records tied to pokemoncreed.net
- Usernames
- Email addresses
- Plaintext passwords
- IP addresses
- Breach dated August 8, 2014
Why This Matters for Pokémon Creed Members
A leak this size, with fully readable passwords attached, is a direct feed for credential stuffing attacks. Many of these accounts likely belonged to younger fans of the game who may have reused the same email and password combination on other gaming platforms, email accounts, or social media. Once an attacker has a working password, account takeover, identity theft, and financial fraud on any linked account all become real possibilities.
How a Database Breach Like This Happens
A database breach happens when someone gains unauthorized access to the records stored behind a website and copies them out, whether through a technical vulnerability, stolen admin access, or in this case, an apparent act of retaliation between rival site owners. Storing passwords in plaintext turns any such breach into a worst-case scenario, since there is no hashing layer to slow an attacker down before the stolen credentials become fully usable.
Check If You Were Affected by the Pokémon Creed Breach
If you or your family ever created an account on pokemoncreed.net, it is worth checking whether that email and password were part of this leak. HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including this one, so you can find out in seconds and change any reused passwords right away.
Breach Breakdown
115,864 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds