A threat actor known as TarTarX gained persistent access to Neopets' IT infrastructure, offering the entire source code base and a user registration database for sale on the dark web. The compromised database contained names, email addresses, dates of birth, and genders.