Prolific hacker steals 218 million personal records in Zynga breach

Gnosticplayers is responsible for some of the biggest data breaches of the year, adding another site to their hit list

Zynga

The personal information of 218 million Zynga users has been stolen in a data breach orchestrated by prolific Pakistani hacker Gnosticplayers.

The company famous for making popular web and mobile games FarmVille, Words with Friends, Draw Something and OMGPOP announced the breach last week but the extent of the stolen data has only recently been revealed.

Advertisement - Article continues below

Speaking to The Hacker News, Gnosticplayers confirmed names, email addresses, usernames, hashed passwords using SHA1 with salt encryption, phone numbers, Facebook IDs (if linked) and password reset tokens (if requested) were stolen.

Gnsoticplayers said anyone who downloaded Words with Friends for both iOS and Android on or before 2 September 2019 have been affected by the breach.

"Cyber attacks are one of the unfortunate realities of doing business today," said Zynga last week. "We recently discovered that certain player account information may have been illegally accessed by outside hackers. An investigation was immediately commenced, leading third-party forensics firms were retained to assist, and we have contacted law enforcement."

"While the investigation is ongoing, we do not believe any financial information was accessed. However, we have identified account login information for certain players of Draw Something and Words With Friends that may have been accessed. As a precaution, we have taken steps to protect these users' accounts from invalid logins. We plan to further notify players as the investigation proceeds."

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

In addition to the more recently developed Zynga games, the older Draw Something and now-defunct OMGPOP users, seven million in total, also had their passwords leaked after being stored in clear text.

"While a breach is always unfortunate, it is encouraging to see that Zynga had sufficient monitoring in place to detect the breach and notify its customers," said Javvad Malik, security awareness advocate at KnowBe4.

"What is not so encouraging is seeing a subset of several million users passwords which had been stored in cleartext. In today's day and age, no company should be storing cleartext passwords. With many users frequently reusing passwords, the breach of this nature can lead to other accounts of individuals being compromised, particularly as the breach also contained email addresses."

Gnosticplayers is the hacker responsible for releasing information gathered from the massive data breaches known as 'the collections' earlier this year. Billions of personal records were stolen through hacks on 45 popular online services.

Advertisement - Article continues below

A month later, the financially-motivated hacker released a further 26 million stolen records and put them up for sale on the dark web marketplace Dream.

A British man named Ashley Mitchell hacked Zynga back in 2011, stole the identities of two Zynga Poker game developers and credits for the game before selling them on Facebook. 

The credit chips were believed to be worth more than 7 million. As a result the 29-year-old from Devon was jailed for two years

Featured Resources

Top 5 challenges of migrating applications to the cloud

Explore how VMware Cloud on AWS helps to address common cloud migration challenges

Download now

3 reasons why now is the time to rethink your network

Changing requirements call for new solutions

Download now

All-flash buyer’s guide

Tips for evaluating Solid-State Arrays

Download now

Enabling enterprise machine and deep learning with intelligent storage

The power of AI can only be realised through efficient and performant delivery of data

Download now
Advertisement

Recommended

Visit/security/355013/10-quick-tips-to-identifying-phishing-emails
Security

10 quick tips to identifying phishing emails

16 Mar 2020
Visit/business-strategy/mergers-and-acquisitions/354941/panda-security-to-be-acquired-by-watchguard
mergers and acquisitions

Panda Security to be acquired by WatchGuard

9 Mar 2020
Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/infrastructure/server-storage/355118/hpe-warns-of-critical-bug-that-destroys-ssds-after-40000-hours
Server & storage

HPE warns of 'critical' bug that destroys SSDs after 40,000 hours

26 Mar 2020
Visit/software/355113/companies-offering-free-software-to-fight-covid-19
Software

These are the companies offering free software during the coronavirus crisis

25 Mar 2020
Visit/software/video-conferencing/355138/zoom-beaming-ios-user-data-to-facebook-for-targeted-ads
video conferencing

Zoom beams iOS user data to Facebook for targeted ads

27 Mar 2020
Visit/cloud/355098/ibm-dedicates-supercomputing-power-to-coronavirus-researchers
high-performance computing (HPC)

IBM dedicates supercomputing power to coronavirus research

24 Mar 2020