Dark Web Intel: 330K Credentials From the PokeCommunity Dump
PokeCommunity (pokecommunity.com) is a long-running online forum dedicated to the Pokemon franchise, serving as one of the largest English-language communities for Pokemon game discussion, fan-made games, and competitive play. In January 2013, PokeCommunity's database was breached, exposing 330,041 user accounts. The stolen data includes email addresses, usernames, IP addresses, and MD5 password hashes. The breach is classified as unverified, but the data has circulated in public breach databases and is widely documented in the online security community.
Why PokeCommunity Breach Is Dangerous
MD5 is one of the weakest hashing algorithms ever used for password storage, and by 2013 it was already known to be unsuitable for security purposes. Attackers with access to a large MD5 hash database can crack most passwords using rainbow tables, which are precomputed lookup tables that match hash values to their original text. A 330,000-record MD5 database like PokeCommunity's can be cracked at scale relatively quickly, converting what looks like a list of scrambled passwords into plain-text credentials ready for use in account attacks.
What Was Exposed in the PokeCommunity Leak
- Email Address
- Username
- IP Address
- MD5 Password Hash
Why This PokeCommunity Data Puts You at Risk
PokeCommunity attracted players of all ages, including teenagers who would now be adults. A person who registered for PokeCommunity in 2013 at age 14 is now an adult with a professional email address, likely still using some of the same passwords or username patterns from their early online years. Credential stuffing tools test email-password pairs from old breaches against current platforms, meaning your PokeCommunity account from 2013 could be the entry point for an attack on an account you actively use today. The IP address field can also be used to establish a seperate historical location record tied to your identity.
How Pokemon Fan Site Data Gets Used in Dark Web Markets
Gaming and fan community forums from the early 2010s are relativly common items in underground credential markets. They are bundled with data from similar breaches into large combo lists, which are then sold or traded for use in credential stuffing campaigns. PokeCommunity's breach occured in 2013 and has been included in multiple aggregated breach databases since then. Each time one of these old datasets is repackaged and redistributed, the credentials within it are tested against a new round of target platforms. The cycle does not stop just because the original source is a decade old.
Check If Your Data Was Exposed
HEROIC's free breach search checks your email against 400 billion+ compromised records, including the PokeCommunity dataset. Search now to see if your account was part of this breach. If you registered on PokeCommunity in 2013 with an email you still use, check whether that email and password combination appears in other recent attacks on your accounts.
Breach Breakdown
330,041 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds