Zynga data breach (2019) — what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
What happened
According to public breach records, the Zynga data breach on September 1, 2019 is reported to have exposed the personal information of 172,869,660 accounts.
In September 2019, game developer Zynga (the creator of Words with Friends) suffered a data breach. The incident exposed 173M unique email addresses alongside usernames and passwords stored as salted SHA-1 hashes. The data was provided to HIBP by dehashed.com.
Passwords in this breach were reportedly stored as SHA-1 hashes.
In September 2019, mobile game developer Zynga disclosed that "certain player account information may have been illegally accessed by outside hackers," in a breach affecting its Words With Friends game. A hacker using the alias "Gnosticplayers" claimed responsibility, and the exposed data — covering roughly 172.9 million accounts — included email addresses, usernames, phone numbers, and passwords stored as salted SHA-1 hashes. Zynga said it engaged third-party forensics firms and contacted law enforcement to investigate the incident.
Sources
What data was exposed
The following types of personal data were compromised:
- Email addresses
- Passwords
- Phone numbers
- Usernames
Breach details
| Detail | Value |
|---|---|
| Breach name | Zynga |
| Date | September 1, 2019 |
| Accounts affected | 172,869,660 |
| Domain | zynga.com |
This summary is compiled from public breach-notification data and known leak databases. Figures reflect what those sources report and may be revised as more is learned. If something here looks wrong or you think your information is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Zynga; it reflects a publicly reported security incident.
What to do now
Based on the data exposed in this breach, here are the steps you should take:
- Change your Zynga password immediately, and change it anywhere else you reused the same login — salted SHA-1 hashes can still be cracked, especially for weaker passwords.
- Enable two-factor authentication on your email and any accounts that shared the breached password.
- Treat unsolicited emails and texts referencing your gaming accounts as potential phishing, since email addresses and phone numbers were exposed.
- Use a unique password per site (a password manager helps) so a future credential leak can't be replayed across your accounts.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.