HackingStolen CredentialsCustomer Data InvolvedCREDENTIALSLowContained
ZYNGA INC.
bd_1bb48f2cbe5297c4 · schema v1 · pii pii-v1
Full breach record for ZYNGA INC. →Zynga disclosed that outside hackers illegally accessed player account information on or about August 31, 2019. The compromised data included Zynga usernames and passwords. No financial information or social security numbers were accessed. Zynga engaged third-party forensics, notified law enforcement, and took steps to protect accounts from invalid logins.
California clockDiscovered Aug 31, 2019 → Notified Sep 30, 201930d ✓ CA 60-day OK4 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-150949
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 30, 2019
- Raw hash
- ce50243afa98d41f8c16b4575832da9dc3cee4680355fd6e18594378624ea50a
Reporting entity
- Name
- ZYNGA INC.norm: zynga
Victim entity
- Name
- ZYNGA INC.norm: zynga
Incident
- Discovered
- Aug 31, 2019
- Materiality determined
- —
- Notification sent
- Sep 30, 2019
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 30d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 31, 2019→ Notified: Sep 30, 201930d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.