Zynga data breach (2019)
In September 2019, the hacker Gnosticplayers breached game developer Zynga, accessing data for nearly 173 million Words With Friends and Draw Something players. Exposed data included emails, usernames, phone numbers, and salted SHA-1 password hashes.
- Victim
- Zynga
- records
- 172.9M
- users
- 172.9M
In September 2019, San Francisco game developer Zynga โ creator of mobile hits Words With Friends, Draw Something, and FarmVille โ was breached by the prolific hacker Gnosticplayers, exposing account data for nearly 173 million players.
What happened
The attacker, known as Gnosticplayers, exploited Zynga's systems and accessed a database covering players who had installed Words With Friends before 2 September 2019. The breach also touched Draw Something and the long-defunct OMGPOP platform. On 12 September 2019, Zynga publicly acknowledged that certain player account information "may have been illegally accessed."
Gnosticplayers โ a known quantity in the cybercrime underground, having sold hundreds of millions of breached accounts since early 2019 โ initially claimed to have stolen data on over 218 million users. A subsequent investigation put the confirmed figure at roughly 173 million unique accounts.
Data exposed
The breach exposed approximately 172,869,660 unique email addresses alongside:
- Usernames
- Passwords stored as salted SHA-1 hashes
- Phone numbers (for many records)
- Password-reset tokens
- Facebook IDs and Zynga account numbers
Zynga stated that financial information was not accessed. The use of salted SHA-1 offered some protection, but SHA-1 is a fast hash and considered cryptographically weak โ meaning a determined attacker could crack a meaningful fraction of weak passwords far more easily than against bcrypt or Argon2.
Impact
With email addresses, phone numbers, and password-reset tokens exposed, affected players faced elevated risk of account takeover, credential-stuffing, and phishing. The presence of reset tokens was particularly concerning, as such tokens can in some circumstances be abused to seize accounts. A proposed class-action lawsuit was filed against Zynga, and the dataset was loaded into Have I Been Pwned so users could check exposure.
Why it matters
The Zynga breach is a landmark in the Gnosticplayers spree that defined 2019's mega-breach landscape, and one of the largest gaming-industry breaches on record. It reinforced two enduring lessons: SHA-1, even salted, is no longer adequate for password storage, and gaming platforms are high-value targets because their large, casual user bases reuse passwords heavily across services. For a company whose games reach hundreds of millions, the breach showed how a single intrusion can cascade into account-takeover risk far beyond Zynga's own ecosystem.
Timeline
Cutoff date: accounts of players who installed Words With Friends before this date are exposed.
The hacker Gnosticplayers breaches Zynga and exfiltrates player account data.
Zynga publicly acknowledges that certain player account information may have been illegally accessed.
Gnosticplayers claims to have stolen data on over 218 million users; investigation later puts the figure near 173 million.
The breach is reported in detail, with about 173 million unique accounts confirmed affected.
A proposed class-action lawsuit is filed against Zynga over the breach; data is loaded into Have I Been Pwned.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/Breach/Zynga
- securityaffairs.comhttps://securityaffairs.com/95696/data-breach/zynga-data-breach.html
- us.norton.comhttps://us.norton.com/blog/emerging-threats/new-report-says-zynga-breach-in-september-affected-172-million-a
- cpomagazine.comhttps://www.cpomagazine.com/cyber-security/password-breach-of-game-developer-zynga-compromises-170-million-accounts/