[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1x1p8n9ydvl0i":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":33,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda48825440","Zynga","Zynga Data Breach","zynga","zynga.com","2019-09-01T00:00:00.000Z","2019-12-19T04:54:45.000Z","2026-07-27T16:11:15.246Z","Verified breach record","https:\u002F\u002Fwww.theverge.com\u002F2019\u002F12\u002F19\u002F21029682\u002Fzynga-hack-words-with-friends-draw-something-password-data-breach",[15,17],"https:\u002F\u002Fwww.cbsnews.com\u002Fnews\u002Fwords-with-friends-hack-zynga-data-breach-exposes-200-million-users\u002F",172869660,"known",null,"unknown","Critical",[24,25,26,27],"Email addresses","Passwords","Phone numbers","Usernames","\u003Cp>The Zynga data breach is a large-scale security incident recorded when account data related to the social gaming company's games such as Words With Friends and Draw Something fell into the hands of unauthorized individuals during the period of September 2019. The confirmed number of records is 172,869,660 unique accounts. The significance of the incident in terms of user security is that email addresses and usernames were included along with password data. This combination creates a strong attack ground for direct takeover attempts of player accounts, risks related to password reuse on other services, and targeted phishing messages. The breach date should be considered September 1, 2019, and the date added to monitoring systems as December 19, 2019.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>In this incident, the verified data categories are email addresses, passwords, phone numbers, and usernames. It has been reported that password data is associated with salted SHA-1 values rather than plaintext; nevertheless, there remains a risk for old and reused passwords. The presence of an email address and username in the same dataset makes it easier for attackers to generate messages resembling those sent by real player profiles. Accounts with phone numbers may face additional risks such as fake support calls, SMS-based scams, and account recovery attempts. Financial information is not verified within the scope; however, account access, in-game identity, social connections, and the use of the same password elsewhere create indirect risks for more critical services.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The Zynga incident involves a large set of user data associated with the company's social game accounts. The verified main service domain is online and mobile games; therefore, industry knowledge should be considered in social gaming and mobile game development rather than retail. The affected number has been verified as 172,869,660 unique accounts. The data fields are limited to email addresses, passwords, phone numbers, and usernames. Although larger claimed numbers or different fields have appeared in the news, only the verified classes should be used in user-facing reports. This distinction does not reduce the risk of the leak; however, it prevents unnecessary exaggeration regarding the number of records, dates, and data fields.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The highest risk is for people who use the same email address and the same or similar password across different platforms in Zynga games. In social games like Words With Friends, Draw Something, and similar games, attackers can send personalized messages because of friends lists, in-game nicknames, and social connections. Game accounts that were created a long time ago and have since been forgotten are also important, as old passwords may often have been reused on other services. Users with phone numbers should be more cautious about fake account recovery messages and support calls. Privacy and account security risks are broader for children, people who share devices with family members, and users who connect social games to Facebook or similar services.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should first change their Zynga account password to a unique and strong password. If the same or a similar password has been used on another game, email, social media, shopping, or financial account, those accounts should also be prioritized for updating. Using a password manager allows you to quickly find repeating passwords and generate unique values for each service. The account recovery email and phone number should be checked, and unfamiliar linked accounts should be removed. In messages that appear to be from Zynga or game support, the address should be verified before clicking on links. Extra caution is needed for SMS verification, reward, gift, or account alert messages, as the phone number may have been compromised.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, game accounts should be protected as diligently as main email and financial accounts. A unique password should be used for each gaming service, and multi-step verification should be enabled wherever possible. Old game accounts should be periodically closed or their passwords renewed. Using the same username on multiple platforms makes it easier for attackers to match accounts; therefore, different usernames and separate email addresses can be preferred for sensitive accounts. Within families, the email, payment information, and social connection settings of game accounts used by children should be reviewed by parents. For organizations, password control policies that prevent employees from using passwords leaked from personal game accounts in work systems are also important.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>When the Zynga result appears on LeakData, it is understood that the email address is included in the 2019 Zynga dataset. This finding, when evaluated together with username and password data, increases the risk of account takeover. The user should first check Zynga and associated game accounts, then other accounts opened with the same email address. Services where the same password is used, email account, social media, game stores, and accounts with payment links should be given priority. The notification date should not be confused with the breach date: the main period of the incident is September 2019, while the verified addition date is December 2019. This distinction is necessary for the true risk timeline to appear correctly on the account security screen.\u003C\u002Fp>","","Zynga Data Breach (172.9 Million Reported Records)","Zynga Data Breach. 172.9 Million reported records were reported. Reported data: Email addresses, Passwords, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fzynga_com.webp",false,{"name":7,"sector":35,"country":36,"website":10,"websiteArchiveUrl":29,"websiteStatus":29,"websiteCheckedAt":20},"Social gaming \u002F Mobile games","United States"]