The Pokemon Uranium Breach Gave Hackers 20,000 Gamer Email Addresses
HEROIC analysts recieved confirmation that a database tied to Pokemon Uranium, the US-based fan-made Pokemon game at pokemonuranium.com, has been circulating in breach aggregation repositories since its original exposure on August 1, 2016. The breach occured when attackers extracted 20,178 user records from the MyBB-powered community platform. Despite the site being taken down due to copyright action shortly after launch, the user database has continued to surface in threat intelligence feeds, credential stuffing lists, and dark web repositories for nearly a decade.
What Attackers Can Do With 20,000 Gamer Email Addresses
Email addresses tied to gaming communities are partcularly useful for targeted phishing because attackers know exactly what the victims care about. With the Pokemon Uranium list, attackers can craft convincing messages referencing the game, fan events, or account restoration offers that lure users into clicking malicious links or handing over credentials. The MyBB password hashes included in the breach are also accessable to cracking tools, meaning attackers who recover the plaintext passwords test them across Steam, Nintendo accounts, email providers, and other platforms the victim is likely to use.
What Was Exposed in the Pokemon Uranium Breach
- Usernames
- Email addresses
- MyBB-hashed passwords
- Forum account details
Why Fan Game and Community Breaches Feed Larger Attacks
Smaller fan communities like Pokemon Uranium often run on limited resources and without dedicated security teams, making them easier to compromise than commercial platforms. Attackers beleive the users of fan gaming sites are the same people with active accounts on larger gaming ecosystems, so breaching one small forum gives them a verified list of gamer identities to test elsewhere. This is how a single database breach from a now-defunct fan project contributes to account takeovers, identity theft, and financial fraud on major gaming and retail platforms years after the site disappears.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a website's backend database, usually by exploiting a known software vulnerability, an unpatched forum plugin, or weak access controls. MyBB, the forum software used by Pokemon Uranium, has a history of vulnerabilities that attackers actively probe. Once inside, the attacker copies the entire user table and distributes the file through criminal networks. The data stays in circulation long after the original site goes offline, as the email addresses and password hashes remain valid for users who haven't changed their credentials.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email against a database of over 400 billion exposed records, including the Pokemon Uranium breach. If your account was part of this leak or any other known breach, you'll find out immediately and receive clear steps to protect yourself before attackers use your data.
Breach Breakdown
20,178 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds