[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2pqlxvpp3kbdh":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":38,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda488252d2","Neopets","Neopets 2013 Data Breach","neopets","neopets.com","2013-05-05T00:00:00.000Z","2016-07-07T23:00:10.000Z","2026-07-21T17:49:00.634Z","Verified breach record","http:\u002F\u002Fmotherboard.vice.com\u002Fread\u002Fneopets-hack-another-day-another-hack-tens-of-millions-of-neopets-accounts",[15,17,18],"https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20160601000000id_\u002Fhttp:\u002F\u002Fmotherboard.vice.com\u002Fread\u002Fneopets-hack-another-day-another-hack-tens-of-millions-of-neopets-accounts","https:\u002F\u002Fwww.reuters.com\u002Ftechnology\u002Fneopets-says-hackers-may-have-stolen-data-69-million-accounts-2022-07-21\u002F",26892897,"known",null,"unknown","Critical",[25,26,27,28,29,30,31,32],"Dates of birth","Email addresses","Genders","Geographic locations","IP addresses","Names","Passwords","Usernames","\u003Cp>\u003Cstrong>The Neopets data breach\u003C\u002Fstrong> is associated with an older event affecting the virtual-pet and gaming community. The canonical date on this page is May 5, 2013, and the verified scope contains 26,892,897 unique email addresses. Data linked to the event was seen in online trading during 2016, but this page covers the older 2013 event. A separately reported later Neopets event is not included in this count, these data classes, or the text on this page.\u003C\u002Fp>\u003Cp>The verified classes are dates of birth, email addresses, genders, geographic locations, IP addresses, names, plaintext passwords, and usernames. This combination creates a high risk of direct account takeover and personalized fraud. A match means that an email address falls within the verified scope; it does not prove that every data type was available for the same person, that an account remains open today, or that the person was affected by the later separate event.\u003C\u002Fp>\u003Ch2>Exposed Data Types and Risks\u003C\u002Fh2>\u003Cp>The verified fields are dates of birth, email addresses, genders, geographic locations, IP addresses, names, plaintext passwords, and usernames. A plaintext password means a readable password value was present rather than a password hash. That creates a particularly serious risk for people who reused the same password elsewhere. Usernames and email addresses can also help an attacker connect different accounts belonging to the same person.\u003C\u002Fp>\u003Cp>A birth date, name, gender, and location can make messages about account support, in-game rewards, age verification, or parental approval appear tailored to a person. An IP address alone does not determine a physical location or current sessions, but it can make target selection easier when combined with other details. Listing the fields does not mean every match includes every field.\u003C\u002Fp>\u003Cp>The verified sources do not list payment cards or physical addresses. That boundary means payment information is not part of the proven scope of this event; it does not prove that no other information at the service was affected. Treat a match as a personal risk signal and do not accept unverified extra data types as facts.\u003C\u002Fp>\u003Ch2>Verified Scope and Limits\u003C\u002Fh2>\u003Cp>The canonical account count for this record is 26,892,897, and the breach date is May 5, 2013. Data appearing in an online trading setting in 2016 does not change the breach date to 2016. Some historical claims referred to a larger raw total, but the verified unique-email scope is the measure used on this page. A raw total is not a count of individual people or active players.\u003C\u002Fp>\u003Cp>Neopets is an online gaming and community service with a global audience. A person appearing in this record is not proof that they have an account at another game service or that they were also present in a later separate Neopets event. Events sharing an email address must not be added together; each needs to be assessed by its own date and verified fields.\u003C\u002Fp>\u003Cp>The verified information does not establish the initial access path, the identity of an attacker, the first copy time for every data file, or which profile details each person supplied. The date identifies the period associated with the event; it does not by itself show a last sign-in or the current access state of an account. These limits do not reduce the plaintext-password risk, but they require care with technical claims that cannot be confirmed.\u003C\u002Fp>\u003Ch2>Users at Elevated Risk\u003C\u002Fh2>\u003Cp>People who reused a Neopets password at an email service, social network, game, shopping site, or another membership deserve the highest priority. The presence of a plaintext password creates a risk that the same value can be tried at other systems. Even people who have not used an old game account for years can be affected when the same email address or password was later used at a newer service.\u003C\u002Fp>\u003Cp>People matched with a birth date, real name, and username should be alert to personalized social-engineering attempts. An attacker may use themes such as in-game items, account security, age restrictions, or birthday rewards. A message containing a correct username or birth date does not prove that its sender represents the real service.\u003C\u002Fp>\u003Cp>Older accounts created during childhood or shared with family members also deserve review. Messages about parent or child accounts can lead people to disclose more personal details. The record does not list physical addresses, so detailed offline targeting cannot be claimed for every person. Online deception and account-recovery attempts still need to be taken seriously.\u003C\u002Fp>\u003Ch2>Immediate Protective Actions\u003C\u002Fh2>\u003Cp>First, identify where a password that may have been used at Neopets was also used. When the same or a similar password appears at any service, change that account password immediately to a long, unique value. Because an email account is a recovery point for many services, review the email password and multi-factor authentication settings as a priority.\u003C\u002Fp>\u003Cp>Review unexpected contact presented as Neopets, game support, an in-game item, or an old-account notice carefully. Before opening a link, evaluate the sender domain, requested action, and actual sign-in address separately. To confirm a suspicious notice, go directly to the known official address of the service rather than using the link in the message.\u003C\u002Fp>\u003Cp>Inspect unfamiliar devices, active sessions, recovery email addresses, and connected applications on important accounts. When unknown access appears, end the session, update recovery details, and keep security alerts enabled. Use the relevant service's official support channel when suspicious activity appears, and never provide a one-time code, password, or identity document to an unsolicited request.\u003C\u002Fp>\u003Ch2>Long-Term Security Practices\u003C\u002Fh2>\u003Cp>Using a different, long password for every online service limits the impact of old plaintext-password exposures. A password manager can generate strong passwords and reduce reuse. Where multi-factor authentication is available, an authenticator application or hardware key is preferable. Text-message codes add protection but cannot prevent every convincing fraud attempt.\u003C\u002Fp>\u003Cp>Review gaming and social-profile privacy regularly. Share details such as birth date, real name, username, friend list, or location only when needed. Reducing use of the same username and profile detail across different communities makes correlation among public information harder. Removing unneeded details from older accounts leaves less context for future targeting.\u003C\u002Fp>\u003Cp>Review account-recovery security at regular intervals. Secondary email addresses, phone numbers, connected devices, active sessions, and forwarding rules need to remain current. Act quickly when an unknown sign-in, forwarding rule, or security-setting change appears. These habits protect every online membership, not only people matched with this Neopets event.\u003C\u002Fp>\u003Ch2>Record Check and User Action\u003C\u002Fh2>\u003Cp>Use the record check on this page to see whether your email address matches the 2013 Neopets event. A match indicates that the address falls within the verified scope; it does not prove that every data type appeared in your row, that a current account was compromised, or that you were also affected by a later separate event. Treat the result as a personal risk signal to prioritize password reuse and account security.\u003C\u002Fp>\u003Cp>If there is no match, it can still help to review older email addresses, alternate usernames, and gaming accounts that are no longer used. No match is not a guarantee that no personal data exists elsewhere online. Unique passwords, multi-factor authentication, routine account review, and independent confirmation of suspicious contact remain the most reliable defense.\u003C\u002Fp>","","Neopets 2013 Data Breach (26.9 Million Reported Records)","Neopets 2013 Data Breach. 26.9 Million reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fneopets_com.webp",false,{"name":7,"sector":40,"country":41,"website":10,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":21},"Gaming \u002F Virtual Pet Community","Global"]