Jump to content

Neopets data breach exposes 69M accounts, source code

Spotty

Summary

The online children's gaming website Neopets has suffered an extensive data breach with the database of 69 million accounts being exposed along with the sites source code. The hacker appears to still have access to Neopets systems (as of 20/07/2022).

 

Quotes

Quote

Virtual pet website Neopets has suffered a data breach leading to the theft of source code and a database containing the personal information of over 69 million members.

On Tuesday, a hacker known as 'TarTarX' began selling the source code and database for the Neopets.com website for four bitcoins, worth approximately $94,000 at today's prices..
The seller claims that this database contains the account information of over 69 million members, including members' usernames, names, email addresses, zip code, date of birth, gender, country, an initial registration email, and other site/game-related information.

Neopets.com data sold on a hacking forum

Source: Bleepingcomputer, via hacking forum

 

Quote

After the news of the breach spread online, the Neopets team, designated by the TNT abbreviation, has confirmed on Discord that they are aware of the security incident and working on resolving it.

"We should note that the effectiveness of changing your Neopets password is currently debatable as long as hackers have live access to the database, as they can simply check what your new password is," reads an announcement on the Neopets Discord server.

"We cannot therefore strictly advise you on the best course of action given the circumstances."

However, if you use the same Neopets password on other sites, you are strongly advised to change your password on those sites to a different one.

 

My thoughts

Nice...
I'm actually surprised Neopets is still going after over 20 years. I remember it from when I was a kid and that was what feels like a long time ago.

 

Changing passwords on Neopets.com won't help as the hacker, who still has access to the system, would still have access to any new password you enter. It is still recommended to change passwords on any other websites you may have used that password on. This is another good reminder that you should use unique passwords for each site/service.

Most people on this forum are probably too old to be playing neopets still, but some might have kids who play it. If your kids played Neopets this might be a good opportunity to talk to them about internet safety and account security.

 

 

Sources

https://www.bleepingcomputer.com/news/security/neopets-data-breach-exposes-personal-data-of-69-million-members/

CPU: Intel i7 6700k  | Motherboard: Gigabyte Z170x Gaming 5 | RAM: 2x16GB 3000MHz Corsair Vengeance LPX | GPU: Gigabyte Aorus GTX 1080ti | PSU: Corsair RM750x (2018) | Case: BeQuiet SilentBase 800 | Cooler: Arctic Freezer 34 eSports | SSD: Samsung 970 Evo 500GB + Samsung 840 500GB + Crucial MX500 2TB | Monitor: Acer Predator XB271HU + Samsung BX2450

Link to comment
Share on other sites

Link to post
Share on other sites

not so Nice

| If someones post is helpful or solves your problem please mark it as a solution 🙂 |

I am a human that makes mistakes! If I'm wrong please correct me and tell me where I made the mistake. I try my best to be helpful.

System Specs

<Ryzen 5 3600 3.5-4.2Ghz> <Noctua NH-U12S chromax.Black> <ZOTAC RTX 2070 SUPER 8GB> <16gb 3200Mhz Crucial CL16> <DarkFlash DLM21 Mesh> <650w Corsair RMx 2018 80+ Gold> <Samsung 970 EVO 500gb NVMe> <WD blue 500gb SSD> <MSI MAG b550m Mortar> <5 Noctua P12 case fans>

Peripherals

<Lepow Portable Monitor + AOC 144hz 1080p monitor> 

<Keymove Snowfox 61m>

<Razer Mini>

Link to comment
Share on other sites

Link to post
Share on other sites

Shit again? this is like the third time for them, poor guys
the first one(2013) was oof but also was back then passwords were stored in plain text (since no one updated that back end, or knew about it as the team had changed hands so many times, same old system from the 90s), at least this time it was salted and hashed which they learned about after.
dont know much about the 2nd one in 2020.

this one, being actively in the system so changing passwords is not helpful is damn impressive.

Link to comment
Share on other sites

Link to post
Share on other sites

Oh yeah, I now remember. This has happened before in past for this company. The pony incident tends to be forgettable, though... (lol).

Also, the hacker doesn't seem the wisest as he uses the GIVE ME BTC OR I WILL XYZ method. Literally one of the most dumbfounded ways to ask for stuff because it's the default mail that you get when somebody spams you that your porn archive is in their hands with your webcam data or whatever the heck. 

Virtual petting doesn't deserve any better though.

Link to comment
Share on other sites

Link to post
Share on other sites

Oh no... Sucks for current users, but I doubt any old timer who used to play neopets years ago have anything to worry... Unless they are dumb enough to still use the same email and password for everything.

 

Last I checked neopets to replay an old game, half the games didn't work because they were still flash based after flash got trashed on our browsers. No idea if they ever fixed that.

CPU: AMD Ryzen 3700x / GPU: Asus Radeon RX 6750XT OC 12GB / RAM: Corsair Vengeance LPX 2x8GB DDR4-3200
MOBO: MSI B450m Gaming Plus / NVME: Corsair MP510 240GB / Case: TT Core v21 / PSU: Seasonic 750W / OS: Win 10 Pro

Link to comment
Share on other sites

Link to post
Share on other sites

Neopets is still around? Don't even know what username or password I would have used back then....

Link to comment
Share on other sites

Link to post
Share on other sites

21 minutes ago, TetraSky said:

Oh no... Sucks for current users, but I doubt any old timer who used to play neopets years ago have anything to worry... Unless they are dumb enough to still use the same email and password for everything.

 

Last I checked neopets to replay an old game, half the games didn't work because they were still flash based after flash got trashed on our browsers. No idea if they ever fixed that.

I just checked and nope, most of the games were lost to the transition.
I did go back to neopets for a while as an adult in college in the mid 2010s, but neopets getting bought by jumpstart and most of TNT getting lost in the transition and half the stuff breaking in the server transfer soured me. Jumpstart really had zero idea what to do with it at the time. I heard they tried to bring back some of the old style events, but I wasnt there to participate. 

Link to comment
Share on other sites

Link to post
Share on other sites

Quote

I'm also selling the full access to the database, so you can modify data, credits or in-game pets, attributes... EVERYTHING you want.

is the target market for all the user data and source code really the same people that would want to give themselves all the money and pets?

🌲🌲🌲

 

 

 

◒ ◒ 

Link to comment
Share on other sites

Link to post
Share on other sites

Oh no! Wait neopets is still a thing? That's like hearing newgrounds had a data breach and they stole everyone's flash game highscores. I'm fairly sure most people will be able to recover from childhood password losses.

The best gaming PC is the PC you like to game on, how you like to game on it

Link to comment
Share on other sites

Link to post
Share on other sites

Oh, maybe they can find my account from elementary school and reset my PW for me since I forgot everything.

 

Also, isn't neopets owned by the Church of Scientology

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, rcmaehl said:

 

 

Also, isn't neopets owned by the Church of Scientology

No, and it never was. An early CEO was a scientologist, the church itself had very little influence on it, and that CEO was largely kowtowed by the two creative leads who made neopets anyways.

Link to comment
Share on other sites

Link to post
Share on other sites

ouch

Specs: Motherboard: Asus X470-PLUS TUF gaming (Yes I know it's poor but I wasn't informed) RAM: Corsair VENGEANCE® LPX DDR4 3200Mhz CL16-18-18-36 2x8GB

            CPU: Ryzen 9 5900X          Case: Antec P8     PSU: Corsair RM850x                        Cooler: Antec K240 with two Noctura Industrial PPC 3000 PWM

            Drives: Samsung 970 EVO plus 250GB, Micron 1100 2TB, Seagate ST4000DM000/1F2168 GPU: EVGA RTX 2080 ti Black edition

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×