Prolific hacker steals 218 million personal records in Zynga breach

Gnosticplayers is responsible for some of the biggest data breaches of the year, adding another site to their hit list

Zynga

The personal information of 218 million Zynga users has been stolen in a data breach orchestrated by prolific Pakistani hacker Gnosticplayers.

The company famous for making popular web and mobile games FarmVille, Words with Friends, Draw Something and OMGPOP announced the breach last week but the extent of the stolen data has only recently been revealed.

Speaking to The Hacker News, Gnosticplayers confirmed names, email addresses, usernames, hashed passwords using SHA1 with salt encryption, phone numbers, Facebook IDs (if linked) and password reset tokens (if requested) were stolen.

Gnsoticplayers said anyone who downloaded Words with Friends for both iOS and Android on or before 2 September 2019 have been affected by the breach.

"Cyber attacks are one of the unfortunate realities of doing business today," said Zynga last week. "We recently discovered that certain player account information may have been illegally accessed by outside hackers. An investigation was immediately commenced, leading third-party forensics firms were retained to assist, and we have contacted law enforcement."

"While the investigation is ongoing, we do not believe any financial information was accessed. However, we have identified account login information for certain players of Draw Something and Words With Friends that may have been accessed. As a precaution, we have taken steps to protect these users' accounts from invalid logins. We plan to further notify players as the investigation proceeds."

In addition to the more recently developed Zynga games, the older Draw Something and now-defunct OMGPOP users, seven million in total, also had their passwords leaked after being stored in clear text.

"While a breach is always unfortunate, it is encouraging to see that Zynga had sufficient monitoring in place to detect the breach and notify its customers," said Javvad Malik, security awareness advocate at KnowBe4.

"What is not so encouraging is seeing a subset of several million users passwords which had been stored in cleartext. In today's day and age, no company should be storing cleartext passwords. With many users frequently reusing passwords, the breach of this nature can lead to other accounts of individuals being compromised, particularly as the breach also contained email addresses."

Gnosticplayers is the hacker responsible for releasing information gathered from the massive data breaches known as 'the collections' earlier this year. Billions of personal records were stolen through hacks on 45 popular online services.

A month later, the financially-motivated hacker released a further 26 million stolen records and put them up for sale on the dark web marketplace Dream.

A British man named Ashley Mitchell hacked Zynga back in 2011, stole the identities of two Zynga Poker game developers and credits for the game before selling them on Facebook. 

The credit chips were believed to be worth more than 7 million. As a result the 29-year-old from Devon was jailed for two years

Featured Resources

The ultimate law enforcement agency guide to going mobile

Best practices for implementing a mobile device program

Free download

The business value of Red Hat OpenShift

Platform cost savings, ROI, and the challenges and opportunities of Red Hat OpenShift

Free download

Managing security and risk across the IT supply chain: A practical approach

Best practices for IT supply chain security

Free download

Digital remote monitoring and dispatch services’ impact on edge computing and data centres

Seven trends redefining remote monitoring and field service dispatch service requirements

Free download

Recommended

Senate report slams agencies for poor cyber security
cyber security

Senate report slams agencies for poor cyber security

3 Aug 2021
Most employees put their workplace at risk by taking cyber security shortcuts
cyber security

Most employees put their workplace at risk by taking cyber security shortcuts

27 Jul 2021
61% of organizations say improving security a top priority for 2021
cyber security

61% of organizations say improving security a top priority for 2021

29 Jun 2021
ProtectedBy.AI’s CodeLock blocks malware at source code level
software as a service (SaaS)

ProtectedBy.AI’s CodeLock blocks malware at source code level

9 Jun 2021

Most Popular

Best Linux distros 2021
operating systems

Best Linux distros 2021

11 Oct 2021
HPE wins networking contract with Birmingham 2022 Commonwealth Games
Network & Internet

HPE wins networking contract with Birmingham 2022 Commonwealth Games

15 Oct 2021
What is cyber warfare?
Security

What is cyber warfare?

15 Oct 2021