Prolific hacker steals 218 million personal records in Zynga breach

Gnosticplayers is responsible for some of the biggest data breaches of the year, adding another site to their hit list

Zynga

The personal information of 218 million Zynga users has been stolen in a data breach orchestrated by prolific Pakistani hacker Gnosticplayers.

The company famous for making popular web and mobile games FarmVille, Words with Friends, Draw Something and OMGPOP announced the breach last week but the extent of the stolen data has only recently been revealed.

Advertisement - Article continues below

Speaking to The Hacker News, Gnosticplayers confirmed names, email addresses, usernames, hashed passwords using SHA1 with salt encryption, phone numbers, Facebook IDs (if linked) and password reset tokens (if requested) were stolen.

Gnsoticplayers said anyone who downloaded Words with Friends for both iOS and Android on or before 2 September 2019 have been affected by the breach.

"Cyber attacks are one of the unfortunate realities of doing business today," said Zynga last week. "We recently discovered that certain player account information may have been illegally accessed by outside hackers. An investigation was immediately commenced, leading third-party forensics firms were retained to assist, and we have contacted law enforcement."

"While the investigation is ongoing, we do not believe any financial information was accessed. However, we have identified account login information for certain players of Draw Something and Words With Friends that may have been accessed. As a precaution, we have taken steps to protect these users' accounts from invalid logins. We plan to further notify players as the investigation proceeds."

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

In addition to the more recently developed Zynga games, the older Draw Something and now-defunct OMGPOP users, seven million in total, also had their passwords leaked after being stored in clear text.

"While a breach is always unfortunate, it is encouraging to see that Zynga had sufficient monitoring in place to detect the breach and notify its customers," said Javvad Malik, security awareness advocate at KnowBe4.

"What is not so encouraging is seeing a subset of several million users passwords which had been stored in cleartext. In today's day and age, no company should be storing cleartext passwords. With many users frequently reusing passwords, the breach of this nature can lead to other accounts of individuals being compromised, particularly as the breach also contained email addresses."

Gnosticplayers is the hacker responsible for releasing information gathered from the massive data breaches known as 'the collections' earlier this year. Billions of personal records were stolen through hacks on 45 popular online services.

Advertisement - Article continues below

A month later, the financially-motivated hacker released a further 26 million stolen records and put them up for sale on the dark web marketplace Dream.

A British man named Ashley Mitchell hacked Zynga back in 2011, stole the identities of two Zynga Poker game developers and credits for the game before selling them on Facebook. 

The credit chips were believed to be worth more than 7 million. As a result the 29-year-old from Devon was jailed for two years

Featured Resources

Preparing for long-term remote working after COVID-19

Learn how to safely and securely enable your remote workforce

Download now

Cloud vs on-premise storage: What’s right for you?

Key considerations driving document storage decisions for businesses

Download now

Staying ahead of the game in the world of data

Create successful marketing campaigns by understanding your customers better

Download now

Transforming productivity

Solutions that facilitate work at full speed

Download now
Advertisement

Recommended

Visit/security/ransomware/356292/university-of-california-gets-fleeced-by-hackers-for-114-million
ransomware

University of California gets fleeced by hackers for $1.14 million

30 Jun 2020
Visit/security/cyber-security/356289/australia-announces-135b-investment-in-cybersecurity
cyber security

Australia announces $1.35 billion investment in cyber security

30 Jun 2020
Visit/cloud/cloud-security/356288/csa-and-issa-form-cybersecurity-partnership
cloud security

CSA and ISSA form cyber security partnership

30 Jun 2020
Visit/security/ethical-hacking/356252/poorly-secured-banking-apps-lead-to-cyber-threats
ethical hacking

Mobile banking apps are exposing user data to attackers

26 Jun 2020

Most Popular

Visit/mobile/google-android/356373/over-2-dozen-additional-android-apps-found-stealing-user-data
Google Android

Over two dozen Android apps found stealing user data

7 Jul 2020
Visit/laptops/29190/how-to-find-ram-speed-size-and-type
Laptops

How to find RAM speed, size and type

24 Jun 2020
Visit/cloud/356260/the-road-to-recovery
Sponsored

The road to recovery

30 Jun 2020