Connect with us

WINNING COMBINATION - SOFTSWISS develops innovative iGaming software products for online casino, sports betting, and beyond. Our products can be delivered as standalone solutions or combined into a single iGaming Platform.

The future of sports betting: BETBY sportsbook is focused on innovation through deep industry knowledge, state-of-the-art software & endless customization possibilities.

Latest News

Animal Jam data breach: 100,000 de-hashed user records leaked, 900,000 more sold on hacker forum

Published

on

Animal Jam data breach: 100,000 de-hashed user records leaked, 900,000 more sold on hacker forum
Reading Time: 3 minutes

A database containing 900,000 user records from the free-to-play game Animal Jam is being sold on hacker forums, with another 100,000 records leaked as a proof-of-concept sample.

Animal Jam is a free-to-play pet simulator developed by WildWorks, a US-based game development studio. The game is available on iOS, Android, PC, and Mac, and has over 130 million registered accounts across all supported platforms.
Recently, the game suffered a data breach where a database containing more than 50 million stolen player records, including email addresses and hashed passwords, has been leaked on a hacker forum.

It seems that it took about a week for a second hacker to de-hash about a million passwords from the previous database and put the plain-text data for sale on another hacker forum: the user records stored in the file that was posted on the hacker forum on November 17 include the players’ email addresses and passwords in plain text.
To see if your email address has been exposed in this or other security breaches, use our personal data leak checker.

What data is contained in the leak?
The file posted on the hacker forum contains what appears to be 100,000 Animal Jam user records, including email addresses and presumably de-hashed passwords stored in plain text.

Such combinations of decrypted user credentials are also known as combo-lists, giving attackers ready-made, machine-readable strings. Combo-lists are typically used as input for automated authentication requests in various malicious activities, such as credential stuffing attacks.

What’s the impact of the leak?
Fortunately, the data found in the leaked file does not contain deeply sensitive information like document scans or credit card numbers. However, it can still be used against Animal Jam players in a variety of ways, such as:

  • Carrying out credential stuffing attacks in order to hack players’ accounts in other games
  • Holding players’ Animal Jam accounts ransom
  • Spamming the victims’ email inboxes with malicious emails

Animal Jam is a free-to-play game that is targeted towards children and incorporates microtransactions. This means that selling stolen game accounts with unlocked premium features and cosmetics back to the affected players or their parents could net malicious actors a lot of money.

What to do if you have been affected?
If you (or your child) have an Animal Jam account and your data has been leaked on this hacker forum, we recommend you:
Change your Animal Jam and email passwords immediately and consider using a password manager to create long, complex passwords
If you have been using an identical password for any other games or online services, change it there as well.
Watch out for potential phishing emails. Do not click on anything suspicious or respond to anyone you don’t know.
Enable two-factor authentication (2FA) on all your online accounts.

De-hashing: The danger of using weak passwords
Judging from the Animal Jam combo-list sample posted on the hacker forum, the vast majority of the de-hashed passwords were weak and contained commonly used words and word-number combinations. While hashing is similar to encryption in that it scrambles input data into semi-randomized output data, there’s a significant difference: hashing is a one-way process.

Competent threat actors are able to de-hash weak passwords by taking acquired lists of password hashes and comparing them with hashes of known weak hash combinations. This is because of the difference between hashing and encryption: identical combinations of symbols will have the same hash value. This means that if a certain commonly used password has been de-hashed once, every other identical password can be de-hashed using the same value.

In fact, there are software tools that are designed specifically for these kinds of tasks. An attacker only needs to upload two text files (called “dictionaries”). The first dictionary is typically composed of hashed password column entries from a hacked database. In this case, it would be the hashed passwords from the previous Animal Jam breach.

The second column contains commonly used passwords or combinations of words, symbols and numbers. These combinations, when joined together, form the second dictionary.

The de-hashing tool takes the second dictionary and the hashes already known by the attacker and compares it with the first dictionary hashes. If any of the hashes match, the password is identified by the program and is associated with the plain text value, giving the attacker all the de-hashed passwords in plain text.

This might be how the threat actor who is selling the Animal Jam combo-list acquired a million passwords in a relatively short amount of time since the Animal Jam data breach.
Which brings us to the moral of the story: never use weak passwords. And if you’re as bad at creating and remembering strong passwords as we are… please, for the love of all that is holy, use a password manager.

 

Source

George Miller started his career in content marketing and has started working as an Editor/Content Manager for our company in 2016. George has acquired many experiences when it comes to interviews and newsworthy content becoming Head of Content in 2017. He is responsible for the news being shared on multiple websites that are part of the European Gaming Media Network.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Advertisement

Advertisement

EveryMatrix at ICE 2025 in Barcelona: Explore advanced iGaming technologies and solutions, including Casino, Sports, Platform, Managed Services, and more. Visit EveryMatrix at stands 2G32, 5K10, and K36.

Advertisement

Launch your iGaming business swiftly and effortlessly with our comprehensive turnkey solutions

Trending (Top 7)

Discover the Magic of EuropeanGaming.eu – Your Gateway to the Gaming Universe

At the heart of the ever-evolving gaming and gambling industry lies EuropeanGaming.eu, a trailblazing online platform that has become the go-to destination for industry professionals, enthusiasts, and stakeholders. As part of HIPTHER, we’re redefining how the gaming world connects, informs, and inspires.

More Than News – A Hub of Insight and Innovation

Reaching over 300,000 readers monthly, EuropeanGaming.eu goes beyond headlines to deliver compelling stories, expert insights, and the latest industry news. From regulatory updates and compliance breakthroughs to the pulse-pounding world of esports and technological advancements, we provide comprehensive coverage of the topics that matter most:

  • Online and Land-Based Gaming
  • Betting and Esports
  • Regulatory and Compliance Updates
  • Cutting-Edge Technology in Gaming

Whether it’s daily news, exclusive interviews with industry leaders, in-depth event reports, or press releases that set the tone for the future, our content resonates with a global audience while maintaining a focus on Europe’s dynamic gaming market.

Bringing the Industry Together

Our impact doesn’t stop at digital content. EuropeanGaming.eu is a proud host of virtual meetups and industry-leading conferences that spark dialogue, foster collaboration, and drive innovation. Through detailed reports and live events, we create a space where operators, suppliers, regulators, and professional services come together to shape the future of gaming.

Why EuropeanGaming.eu?

At HIPTHER, we believe in empowering the gaming community with knowledge, connection, and opportunity. EuropeanGaming.eu embodies this spirit by serving as a one-stop resource for the latest trends, market developments, and global perspectives. Whether you’re an industry veteran, a rising operator, or a gaming enthusiast, this is where you find the stories that drive progress.

Get In Touch

Let’s shape the future of gaming together!


Copyright © 2015 - 2025
European Gaming is proudly part of HIPTHER. Registered in Romania under Proshirt SRL, Company Number: 2134306, EU VAT ID: RO21343605.
Office Address: Blvd. 1 Decembrie 1918 nr.5, Târgu Mureș, Romania

Join us as we celebrate a decade of delivering excellence and embrace the magic of what’s to come in 2025 and beyond!

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.