Zynga suffered a major breach that exposed data from about 173 million user accounts, including players of Words With Friends. The compromised information included email addresses, usernames, and passwords stored as salted SHA-1 hashes; some records also contained Facebook IDs and phone numbers. Have I Been Pwned added the incident to its breach corpus after receiving the data from dehashed.com, listing 172,869,660 unique accounts tied to the intrusion.
Reports linked the attack to the actor known as Gnosticplayers, who was also said to have accessed additional Zynga databases beyond the main trove. Those claims included a smaller OMGPop database containing roughly 7 million plaintext passwords tied to the discontinued game. The incident became one of the largest gaming-related credential exposures on record and underscored the ongoing risk that hashed or legacy password stores can still be abused in large-scale account compromise efforts.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Have I Been Pwned listed the Zynga breach as affecting about 173 million unique email addresses, with exposed usernames and salted SHA-1 password hashes. The data was later provided to HIBP by dehashed.com.
On 2019-10-01, reporting indicated that the Zynga breach exposed data belonging to more than 200 million players, primarily tied to Words With Friends. This clarified and escalated the scale of the incident beyond Zynga's initial September disclosure.
Around the same period, the actor using the alias Gnosticplayers claimed to have stolen additional smaller Zynga databases, including data from the discontinued OMGPop service with about 7 million plaintext passwords. This expanded the apparent scope of the incident beyond the initially discussed game data.
In September 2019, Zynga disclosed that it had suffered a data breach affecting user accounts, including players of Words With Friends. The company initially acknowledged the hack without publicly stating its full scale.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
haveibeenpwned.com
Open sourcetheguardian.com
Open sourcecpomagazine.com
Open sourcecbsnews.com
Open sourcecnet.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.