2 min read

Data Breach: Bad actor leaks 23 million account credentials from Webkinz children"s platform

Alina BÎZGĂ

April 22, 2020

Ad One product to protect all your devices, without slowing them down.
Free 90-day trial
Data Breach: Bad actor leaks 23 million account credentials from Webkinz children"s platform

Over the weekend, ZDNet learned that nearly 23 million usernames and hashed passwords of the Webkinz World online children”s game platform were leaked on a popular hacking forum.

Released by Canadian toy company Ganz in 2005, Webkinz World has consistently grown in popularity, allowing little ones to explore a virtual world with their plush toy after entering a special code online.

According to Under the Breach, a bad actor posted 1GB file containing no less than 22,982,319 usernames along with the hashed passwords of players enjoying the Webkinz World variety of online kids” games.

Check now if your personal info has been stolen or made public on the internet, with Bitdefender”s Digital Identity Protection tool.

In a Webkinz tweet on April 19, the platform does not appear to acknowledge the data breach or leak: “We are aware of a story today alleging a data breach,” Webkinz wrote. “Your account security is of utmost importance to us, and we are investigating thoroughly. Please note that we have never asked for addresses, phone numbers or last names, and Webkinz accounts are not connected to eStore account data in any way. If you have any concerns, we encourage you to change your account password using the button on the Webkinz Login Screen.”

However, according to the initial publication, the platform”s staff had already detected the security incident and managed to fix the vulnerability in their system to prevent any further damage.

Unfortunately, it is not clear if the leaked pairings of username and passwords are scraped only from the platform”s active pool of players.

After 18 months of inactivity we will archive an account,” reads the notice on the gaming platform. “For security purposes, during the archiving process, we remove all information associated to the account other than then User Name and Password. Please note that if an account remains inactive for a period of 7 years, Ganz will then delete that account.”

The incident stands to prove that, no matter the industry or online platform, nobody is safe from cyber criminals. Hackers will attempt to penetrate any system and, as with any data breach or leak, users should be aware of the risks.

Even if the passwords are hashed, they are not breach proof. A hacker can still attempt to crack a password through a brute force attack. If he succeeds, and you have used the same email address and password to log in on another platform, he can easily take over other existing accounts.

It”s best to avoid using the same email address and password combination for multiple online accounts. But if you do, try to create a strong password (it can even be a phrase), and enable a multi-factor authentication method.

tags


Author



Right now

Top posts

Enhance your cyber resilience and privacy on Computer Security Day in four easy steps

Enhance your cyber resilience and privacy on Computer Security Day in four easy steps

November 29, 2022

2 min read
How to monitor your online privacy during your Thanksgiving trip

How to monitor your online privacy during your Thanksgiving trip

November 22, 2022

3 min read
Just your yearly dose of Black Friday spam: Cybercrooks get ahead of the game to steal shoppers’ info

Just your yearly dose of Black Friday spam: Cybercrooks get ahead of the game to steal shoppers’ info

November 16, 2022

6 min read
Bitdefender VPN in 2022: the new, the improved, and the soon-to-be

Bitdefender VPN in 2022: the new, the improved, and the soon-to-be

November 14, 2022

5 min read
Cyber Tips for a Spook-Free Halloween

Cyber Tips for a Spook-Free Halloween

October 26, 2022

3 min read
August Spam Debrief: Bitdefender Labs Warns of Fraud Campaigns Exploiting the Russia-Ukraine War

August Spam Debrief: Bitdefender Labs Warns of Fraud Campaigns Exploiting the Russia-Ukraine War

August 31, 2022

4 min read

FOLLOW US ON

SOCIAL MEDIA


You might also like

Your phone number got leaked? Here’s what cybercriminals can do with it and how you can stop them Your phone number got leaked? Here’s what cybercriminals can do with it and how you can stop them
Alina BÎZGĂ

December 05, 2022

3 min read
Threat actor publicly shares stolen data of 5.4 million Twitter users Threat actor publicly shares stolen data of 5.4 million Twitter users
Alina BÎZGĂ

November 28, 2022

3 min read
500 million WhatsApp mobile phone numbers are up for grabs on the dark web 500 million WhatsApp mobile phone numbers are up for grabs on the dark web
Alina BÎZGĂ

November 25, 2022

2 min read