HomeSecurityNeopets: Breach exposes personal information of 69 million members

Neopets: Breach exposes personal information of 69 million members

Virtual pet website Neopets suffered a data breach that led to the theft of source code and a database containing the personal information of more than 69 million members.

Neopets is a popular website where members can own, raise, and play games with their virtual pets. Neopets recently released NFTs that will be used as part of an online Metaverse.

On Tuesday, a hacker known as “TarTarX” began selling the source code and database for the website Neopets.com for four bitcoins, worth about $94,000 at today’s prices.

In a conversation with BleepingComputer, TarTarX says they stole the database and about 460MB of source code for the website neopets.com.

The seller claims that this database contains the account of over 69 million members, and in a screenshot shared with BleepingComputer, you can see the data including usernames, first names, email addresses, zip code, date of birth, gender, country, an original registration email, and other information related to the site/game.

Neopets: Breach exposes personal information of 69 million members
Neopets: Breach exposes personal information of 69 million members

While the hacker did not reveal how they gained access to the site, they told us that they did not demand a ransom for the data from Jumpstart, the owners of Neopets, but did receive interest from potential buyers.

BleepingComputer has not been able to independently verify the authenticity of the database at this time. However, Pompompurin, the owner of the Breached.co, verified the hacker's claims by registering an account on Neopets.com and TarTarX sent the new file created from the database.

“I made an account on the site and they sent me the full listing,” Pompompurin posted on the Breached.co forums.

Furthermore, this verification showed that TarTarX continued to access the neopets.com website even after they started selling the data.

After news of the breach spread online, the Neopets team, designated by the abbreviation TNT, confirmed on the unofficial Neopets Discord server that it is aware of the security incident and is working to resolve it.

Discord's volunteer moderators warn that changing passwords on Neopets may not help secure your account if attackers still have access to their servers.

"We should note that the effectiveness of changing your Neopets password is currently debatable, as hackers have live access to the database, as they can simply check what your new password is," reads a statement on the Neopets Discord server.

"We cannot therefore strictly advise you on the best course of action given the circumstances.".

Neopets: Breach exposes personal information of 69 million members
Neopets: Breach exposes personal information of 69 million members

However, if you use the same Neopets password on other websites, we recommend that you change your password on those websites to something else.

Neopets members can follow a topic on the Jelleyneo website that offers help for Neopets or on the Jelleyneo Twitter account , where other members follow any official updates from Neopets staff.

This is not the first data breach for Neopets, with member data being leaked online in 2016 from a breach that occurred in 2012.

Although this breach appears to be new, Neopets has a history of unauthorized access to its systems.

See also: Google search results: YouTube advertising leads to fraud

A Reddit user named neo_truths told BleepingComputer that they had “read” access to the database for at least a year after finding exploits in the leaked website’s source code.

neo_truths said they use this access to analyze and share information about the game's mechanics on Reddit.

However, neo_truths reported that they used someone else's exploit to inject code into a PHP eval() function to modify Neopets as an April Fool's joke.

Neopets: Breach exposes personal information of 69 million members
Neopets: Breach exposes personal information of 69 million members

Unfortunately, neo_truths says the code is huge and spread across multiple servers, with only a few developers managing it. This lack of staffing has led to numerous breaches by multiple individuals in the past, with one actively used exploit being reported to developers who eventually fixed it.

"Neopets is full of abuse and many people have had (and may still have) access to it for years. The only difference is that they are using it privately (mostly for off-site production and sale) and I am trying to address some known issues with real data," neo_truths explains in a comment on Reddit.

See also: Albania: Government suffers “massive cyberattack”

"I've already reported 2 exploits that allowed access to databases that other people had used (one of them for months/years). I might not have found them if I hadn't had access myself."

"I could always choose to reveal my own method, thereby losing access, which would be the right thing to do, but at the same time would let others have the data freely."

While neo_truths has had access to the Neopets database for some time, he told BleepingComputer that he was not involved in this recent breach and believes that the threat actors gained access using a flaw unrelated to the Neopets code.

"The vulnerability this time is not related to neo's code, it's just a general vulnerability that many websites have," neo_truths told BleepingComputer.

Source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS