[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1w2xme358mfbb":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":30,"seoTitle":16,"seoTitleEn":31,"seoDescription":16,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":4,"isSpamList":34,"isMalware":34,"company":35},"68e3266eda11adda4882531e","pokemon-creed","Pokémon Creed Data Breach","pokmon-creed","pokemoncreed.net","2014-08-08T00:00:00.000Z","2014-08-10T00:03:59.000Z","2026-07-03T23:23:17.190Z","2026-07-18T23:56:15.707Z","Third party breach","",[],116465,"known",null,"unknown","High",[24,25,26,27,28,29],"Email addresses","Genders","IP addresses","Passwords","Usernames","Website activity","\u003Cp>The Pokémon Creed data breach is related to the exposure of user data belonging to a Pokémon-themed fan RPG website in August 2014. The scope is approximately 116,465 accounts. This record was treated as a fan game community account breach; the company realigned the country, industry, website, and data class fields with the verified scope. It was marked as sensitive due to plaintext passwords and the context of young users.\u003C\u002Fp>\u003Cp>The text was rewritten to directly explain risk, scope, and action to the user. The website field was stored as pokemoncreed.net; a format that would cause a double https on the link side was not used because the protocol was not added. The sector was corrected to gaming and fan RPG instead of social media; the country was set to Global.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data seen in this record are email addresses, gender information, IP addresses, passwords, usernames, and site activity. It was assessed that the passwords are in plain text; this poses a high risk for reused passwords. Unverified payment cards, bank accounts, private messages, health records, or additional profile fields were not added to the data class list; only supported fields were retained.\u003C\u002Fp>\u003Cp>Username, site activity, and IP information may cause the game ID to be matched with different platforms. An email address alone poses a risk of unwanted messages; when combined with phone, address, IP, date of birth, password, travel plans, partial card data, or device data, it becomes easier for an attacker to generate personalized messages for the user. The risk assessment was conducted based on this combined effect.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The scope was verified with account 116,465 dated August 2014. Confirmed areas were preserved while unconfirmed areas were excluded. The event was not combined with datasets with similar names, events from different periods of the same company, or incorrect industry references.\u003C\u002Fp>\u003Cp>The registration is limited to the domain pokemoncreed.net and was not presented as a violation of official Pokémon brand systems. The domain name, company name, and industry information were kept in the narrowest accurate context possible. In areas of uncertainty, the verified flag or website domain was set accordingly; thus, no uncertain brand liability was shown to the user.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>User groups at risk may include Pokémon Creed players, members of fan RPG communities, and people who use the same username in other games. Matched users should also evaluate other accounts where they use the same email, phone, username, or password pattern outside of the relevant service.\u003C\u002Fp>\u003Cp>The possibility that young users may have reused old game passwords on social media or email accounts should be considered. If there is a corporate email, educational account, hotel reservation, telecom subscription, gaming community, open-source donation, or tracking software context, the risk of social engineering may increase. Details that appear correct are not a sign of trust on their own.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should change their Pokémon Creed password and all games, email, and social accounts where the same password is used. In records with a password field, all accounts using the same password should be updated; in records without a password field, the focus should be on the risk of email, phone, fake notifications, privacy, and identity matching.\u003C\u002Fp>\u003Cp>Instead of clicking on the links in the message, the address of the relevant service should be typed manually or the record in a trusted password manager should be used. Messages about shipping, account alerts, game rewards, support, donor notifications, travel reservations, security notifications, or subscription renewals should not be accepted without verification from an independent channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Official brand account passwords should not be used in fan games; a separate password and username should be preferred for each game. Users should regularly clean up old accounts, unnecessary profile fields, duplicate usernames, and outdated phone and address information. A unique password for each service and two-factor authentication wherever possible should be the basic rule.\u003C\u002Fp>\u003Cp>From the perspective of service providers, data minimization, strong password protection, monitoring of access logs, deletion of unnecessary fields, and readiness of user notification processes are required. Fan game communities should make security notifications without misleading user trust due to the official brand perception. Accurate scope explanation is also part of the security work; exaggerated or incomplete information can lead the user to take the wrong action.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The user should first check this record with their email address. If a match is found, it should be assumed that the plain text password, site activity, username, and IP information may be at risk. Not finding a match does not completely rule out the use of a different email or reuse of an old password; critical accounts should also be reviewed.\u003C\u002Fp>\u003Cp>This record has been verified and updated as sensitive; it was not confused with official brand systems. In this arrangement, data fields were left as English canonical classes, the description visible to the user was written in Turkish and original, unverified fields were not added, and the sensitivity flag was used only when supported by the risk context.\u003C\u002Fp>","Pokémon Creed Data Breach (116.5 Thousand Reported Records)","Pokémon Creed Data Breach. 116.5 Thousand reported records were reported. Reported data: Email addresses, Genders, IP addresses. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fpokemoncreed_net.webp",false,{"name":36,"sector":37,"country":38,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"Pokémon Creed","Gaming \u002F Fan RPG","Global"]