Neopets data breach (2013) — what was exposed and what to do

Updated Corrections

June 22, 2026

We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.

What happened

According to public breach records, the Neopets data breach on May 5, 2013 is reported to have exposed the personal information of 26,892,897 accounts.

In May 2016, a set of breached data originating from the virtual pet website "Neopets" was found being traded online. Allegedly hacked "several years earlier", the data contains sensitive personal information including birthdates, genders and names as well as almost 27 million unique email addresses. Passwords were stored in plain text and IP addresses were also present in the breach.

Passwords in this breach were reportedly stored in plaintext.

In May 2016, a set of breached data originating from the virtual pet website Neopets was found being traded online, with the underlying compromise dated to May 2013. The breach exposed approximately 26.9 million accounts, including usernames, email addresses, names, dates of birth, genders, geographic locations and IP addresses. Notably, the account passwords were stored in plain text rather than hashed, meaning credentials were directly readable once the data surfaced.

Sources

What data was exposed

The following types of personal data were compromised:

  • Dates of birth
  • Email addresses
  • Genders
  • Geographic locations
  • IP addresses
  • Names
  • Passwords
  • Usernames

Breach details

Detail Value
Breach name Neopets
Date May 5, 2013
Accounts affected 26,892,897
Domain neopets.com

This summary is compiled from public breach-notification data and known leak databases. Figures reflect what those sources report and may be revised as more is learned. If something here looks wrong or you think your information is involved, contact our support team.

We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Neopets; it reflects a publicly reported security incident.

What to do now

Based on the data exposed in this breach, here are the steps you should take:

  • Change your Neopets password immediately, and because the passwords were exposed in plain text, change that same password anywhere else you reused it.
  • Enable two-factor authentication on your email and any accounts that shared the exposed password, since reused credentials are the primary risk from this leak.
  • Treat email tied to this account as a phishing and spam target, and be wary of messages that reference your username, date of birth, or location to appear legitimate.
  • Be alert for social-engineering or identity-verification attempts that abuse the leaked date of birth, name, and location, and avoid using those details as security answers elsewhere.

What to do after a breach

A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.

More breaches

Free personal data exposure scan

We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.