Breach directory
Zynga Data Breach (2019)
If you played Words with Friends or Draw Something before September 2019, your account was probably in the Zynga breach. Zynga confirmed it on 12 September 2019 without giving a count, CNET reported.
- Accounts exposed
- 172,869,660
- When it happened
- Sep 2019
- Added to Have I Been Pwned
- Dec 2019
- Data exposed
- Email addresses, usernames, phone numbers, passwords
- Passwords stored as
- SHA-1, salted
- Games named
- Words with Friends and Draw Something, per CNET
Breach data from Have I Been Pwned by Troy Hunt, licensed under CC BY 4.0.
Was your email address in the Zynga breach?
Use the email address tied to your Zynga games, and you will see whether it is in the Zynga record, plus any other breach that has it too.
What happened
Zynga went first. According to CNET, the games company confirmed on 12 September 2019 that account login details for Draw Something and Words with Friends players had been accessed, said law enforcement had been told, and described an investigation that was still open. On its support page Zynga added that it had moved to block invalid logins and that some players would have to choose a new password.
What it did not give was a number. That came from the other side: CNET reported on 1 October 2019 that a hacker had claimed the Zynga breach, citing a report by The Hacker News. According to the claim, the data covered more than 218 million Words with Friends accounts, covering Android and iOS players who installed the game before early September.
Have I Been Pwned loaded the set in December 2019 and counts 172,869,660 unique email addresses. Its figure sits below the claimed account total because it counts each address once, however many games or accounts used it.
In September 2019, game developer Zynga (the creator of Words with Friends) suffered a data breach. The incident exposed 173M unique email addresses alongside usernames and passwords stored as salted SHA-1 hashes.
What was exposed
Four fields make up the Zynga record: email addresses, usernames, phone numbers and password hashes. No payment details appear in the record, which is the part most players worry about first.
The phone number is the field to think about. It turns this record into a way to reach you by text, and a message that mentions your username and the game reads as genuine. Usernames chosen for a casual game also tend to be reused on forums and other apps, which turns one row of the Zynga data breach into a map of where else to try the same login.
How the passwords were stored
Zynga stored passwords as SHA-1 hashes with a salt, according to Have I Been Pwned. The salt does one useful thing: two players with the same password end up with different hashes, so cracking one does not hand over the other, and lookup tables built in advance are useless.
What the salt cannot fix is speed. SHA-1 was designed to run fast, and a single graphics card tests billions of guesses a second against each salted hash. So an attacker simply works through the most likely passwords one account at a time. Short, common or reused passwords from the Zynga breach should be treated as known; a long random one probably held.
Timeline
Sep 2019
Zynga account data taken, per Have I Been Pwned.
Sep 2019
Zynga confirms the breach on 12 September 2019, CNET reports, and forces some password changes.
Oct 2019
CNET reports on 1 October 2019 a claim of more than 218 million Words with Friends accounts taken.
Dec 2019
Have I Been Pwned adds 172,869,660 unique email addresses.
Disclosure lag
Days for the confirmation, about three weeks before anyone put a size on it.
What to do now
Change the Zynga password on any other site where you used it, and switch on two-factor sign-in for your email first, since that inbox resets everything else. Then be suspicious of texts about your games, prizes or account problems; the phone number in this record is how they would reach you.
If your Zynga username doubles as your handle elsewhere, those accounts deserve their own passwords too. Finally, run the free LeakNix check on the address: one record is rarely the only one.
Questions about the Zynga breach
Which Zynga games were affected?
- Zynga's confirmation named Words with Friends and Draw Something, as reported by CNET. The claim that followed focused on Words with Friends players who installed the game before early September 2019.
Were passwords exposed in the Zynga breach?
- Yes, as salted SHA-1 hashes. A salt stops one cracked hash from revealing everyone with the same password, but SHA-1 is fast, so weak passwords can still be recovered.
How many accounts were in the Zynga data breach?
- Have I Been Pwned holds 172,869,660 unique email addresses from it. A hacker claimed more than 218 million accounts; Zynga's confirmation, as CNET reported it, gave no figure.
Related breaches
The Zynga data breach record here (172,869,660 accounts, Sep 2019) is from Have I Been Pwned under CC BY 4.0, with no endorsement of LeakNix implied.
LeakNix