Skip to content
Data breachResolved

Zynga data breach (2019)

In September 2019, the hacker Gnosticplayers breached game developer Zynga, accessing data for nearly 173 million Words With Friends and Draw Something players. Exposed data included emails, usernames, phone numbers, and salted SHA-1 password hashes.

Victim
Zynga
records
172.9M
users
172.9M

In September 2019, San Francisco game developer Zynga โ€” creator of mobile hits Words With Friends, Draw Something, and FarmVille โ€” was breached by the prolific hacker Gnosticplayers, exposing account data for nearly 173 million players.

What happened

The attacker, known as Gnosticplayers, exploited Zynga's systems and accessed a database covering players who had installed Words With Friends before 2 September 2019. The breach also touched Draw Something and the long-defunct OMGPOP platform. On 12 September 2019, Zynga publicly acknowledged that certain player account information "may have been illegally accessed."

Gnosticplayers โ€” a known quantity in the cybercrime underground, having sold hundreds of millions of breached accounts since early 2019 โ€” initially claimed to have stolen data on over 218 million users. A subsequent investigation put the confirmed figure at roughly 173 million unique accounts.

Data exposed

The breach exposed approximately 172,869,660 unique email addresses alongside:

  • Usernames
  • Passwords stored as salted SHA-1 hashes
  • Phone numbers (for many records)
  • Password-reset tokens
  • Facebook IDs and Zynga account numbers

Zynga stated that financial information was not accessed. The use of salted SHA-1 offered some protection, but SHA-1 is a fast hash and considered cryptographically weak โ€” meaning a determined attacker could crack a meaningful fraction of weak passwords far more easily than against bcrypt or Argon2.

Impact

With email addresses, phone numbers, and password-reset tokens exposed, affected players faced elevated risk of account takeover, credential-stuffing, and phishing. The presence of reset tokens was particularly concerning, as such tokens can in some circumstances be abused to seize accounts. A proposed class-action lawsuit was filed against Zynga, and the dataset was loaded into Have I Been Pwned so users could check exposure.

Why it matters

The Zynga breach is a landmark in the Gnosticplayers spree that defined 2019's mega-breach landscape, and one of the largest gaming-industry breaches on record. It reinforced two enduring lessons: SHA-1, even salted, is no longer adequate for password storage, and gaming platforms are high-value targets because their large, casual user bases reuse passwords heavily across services. For a company whose games reach hundreds of millions, the breach showed how a single intrusion can cascade into account-takeover risk far beyond Zynga's own ecosystem.

Timeline

  1. Cutoff date: accounts of players who installed Words With Friends before this date are exposed.

  2. The hacker Gnosticplayers breaches Zynga and exfiltrates player account data.

  3. Zynga publicly acknowledges that certain player account information may have been illegally accessed.

  4. Gnosticplayers claims to have stolen data on over 218 million users; investigation later puts the figure near 173 million.

  5. The breach is reported in detail, with about 173 million unique accounts confirmed affected.

  6. A proposed class-action lawsuit is filed against Zynga over the breach; data is loaded into Have I Been Pwned.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/Breach/Zynga
  2. securityaffairs.comhttps://securityaffairs.com/95696/data-breach/zynga-data-breach.html
  3. us.norton.comhttps://us.norton.com/blog/emerging-threats/new-report-says-zynga-breach-in-september-affected-172-million-a
  4. cpomagazine.comhttps://www.cpomagazine.com/cyber-security/password-breach-of-game-developer-zynga-compromises-170-million-accounts/

Related incidents

Data breachResolved

Under Armour data breach (2025)

In November 2025, the Everest ransomware group claimed to have stolen 343GB of data from apparel maker Under Armour. After no ransom was paid, customer data was leaked in January 2026, exposing roughly 72.7 million unique email addresses with names, dates of birth, genders, locations and purchase histories. This is a separate incident from the 2018 MyFitnessPal breach.

Victim
Under Armour
Records
72.7M
Data breachResolved

Neiman Marcus data breach (2024)

In 2024, the luxury retailer Neiman Marcus had data stolen from its Snowflake cloud environment via stolen credentials. The company reported about 64,000 individuals to regulators, but the leaked dataset exposed roughly 31 million unique email addresses along with names, contact details and gift-card numbers.

Victim
Neiman Marcus
Records
31.2M
Data breachResolved

Famm data breach (2020)

In late 2020, the Japanese family photos website Famm suffered a data breach that subsequently exposed 1.3M customer records, including 535k unique email addresses. Impacted data also included names, dates of birth, genders and passwords stored as SHA-256 hashes.

Victim
Famm
Records
535.2K