Prolific hacker steals 218 million personal records in Zynga breach

Gnosticplayers is responsible for some of the biggest data breaches of the year, adding another site to their hit list

Zynga

The personal information of 218 million Zynga users has been stolen in a data breach orchestrated by prolific Pakistani hacker Gnosticplayers.

The company famous for making popular web and mobile games FarmVille, Words with Friends, Draw Something and OMGPOP announced the breach last week but the extent of the stolen data has only recently been revealed.

Speaking to The Hacker News, Gnosticplayers confirmed names, email addresses, usernames, hashed passwords using SHA1 with salt encryption, phone numbers, Facebook IDs (if linked) and password reset tokens (if requested) were stolen.

Gnsoticplayers said anyone who downloaded Words with Friends for both iOS and Android on or before 2 September 2019 have been affected by the breach.

"Cyber attacks are one of the unfortunate realities of doing business today," said Zynga last week. "We recently discovered that certain player account information may have been illegally accessed by outside hackers. An investigation was immediately commenced, leading third-party forensics firms were retained to assist, and we have contacted law enforcement."

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"While the investigation is ongoing, we do not believe any financial information was accessed. However, we have identified account login information for certain players of Draw Something and Words With Friends that may have been accessed. As a precaution, we have taken steps to protect these users' accounts from invalid logins. We plan to further notify players as the investigation proceeds."

In addition to the more recently developed Zynga games, the older Draw Something and now-defunct OMGPOP users, seven million in total, also had their passwords leaked after being stored in clear text.

"While a breach is always unfortunate, it is encouraging to see that Zynga had sufficient monitoring in place to detect the breach and notify its customers," said Javvad Malik, security awareness advocate at KnowBe4.

"What is not so encouraging is seeing a subset of several million users passwords which had been stored in cleartext. In today's day and age, no company should be storing cleartext passwords. With many users frequently reusing passwords, the breach of this nature can lead to other accounts of individuals being compromised, particularly as the breach also contained email addresses."

Gnosticplayers is the hacker responsible for releasing information gathered from the massive data breaches known as 'the collections' earlier this year. Billions of personal records were stolen through hacks on 45 popular online services.

Advertisement - Article continues below

A month later, the financially-motivated hacker released a further 26 million stolen records and put them up for sale on the dark web marketplace Dream.

A British man named Ashley Mitchell hacked Zynga back in 2011, stole the identities of two Zynga Poker game developers and credits for the game before selling them on Facebook. 

The credit chips were believed to be worth more than 7 million. As a result the 29-year-old from Devon was jailed for two years

Featured Resources

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Three keys to maximise application migration and modernisation success

Harness the benefits that modernised applications can offer

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

The 3 approaches of Breach and Attack Simulation technologies

A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals

Download now
Advertisement

Recommended

Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020
Visit/hardware/354584/windows-10-and-the-tools-for-agile-working
Sponsored

Windows 10 and the tools for agile working

20 Jan 2020
Visit/business-strategy/public-sector/354608/uk-gov-launches-ps300000-sen-edtech-initiative
public sector

UK gov launches £300,000 SEN EdTech initiative

22 Jan 2020
Visit/web-browser/30394/what-is-http-error-503-and-how-do-you-fix-it
web browser

What is HTTP error 503 and how do you fix it?

7 Jan 2020