Breach report
GamingZynga
Zynga data breach exposed 200 million Words with Friends players
Hacker GnosticPlayers claimed to have stolen data on more than 218 million Words With Friends players in September 2019, one of the largest breaches ever to hit a gaming company.
Reported by CBS News
Records exposed
218M
About 218 million accounts (hacker's claim); roughly 173 million unique email addresses
Scale vs. largest on file
- When
- 2019
- How they got in
- Database intrusion by hacker GnosticPlayers
- Sector
- Gaming
In September 2019, mobile game maker Zynga announced that account information for players of Words With Friends and Draw Something may have been accessed by outside hackers. The disclosure followed reports that a hacker using the name GnosticPlayers had broken into Zynga's systems and obtained a database covering more than 218 million Words With Friends users. The affected players were those on Android and iOS who had installed the game on or before September 2, 2019.
The stolen records included names, email addresses, login IDs, passwords hashed with salted SHA-1, some phone numbers, some Facebook IDs, and Zynga account IDs. The hacker also claimed to have taken data tied to Draw Something and the older OMGPOP gaming service, including a set of accounts whose passwords had been stored in plain text. Zynga said no financial information was accessed. Breach-notification service Have I Been Pwned later counted about 173 million unique email addresses in the data.
GnosticPlayers was a prolific seller of stolen databases. Earlier that year the same actor had marketed hundreds of millions of records taken from dozens of websites, including Canva and MyFitnessPal. In the Zynga case, the hacker told reporters that the intrusion had given access to the Words With Friends player database as well as other company data.
Zynga said it had engaged forensic firms, notified law enforcement and taken steps to protect accounts, including forcing password resets for some players it believed were at higher risk. The company did not say exactly how the attackers got in. A class-action lawsuit was filed in federal court in California, accusing Zynga of failing to adequately protect player data and of relying on outdated password hashing.
The incident was among the largest breaches ever to hit a gaming company and illustrated how casual mobile games accumulate huge troves of personal data, often linked to social media accounts. The mix of weakly hashed and plaintext passwords made the data especially useful for credential-stuffing attacks against other services. For players, the lesson was familiar: unique passwords limit the spillover when a game or app is compromised, and legacy services acquired by larger companies can carry old security weaknesses forward for years.