Hacker Puts Millions of Usernames, Passwords From Webkinz World Online: Report

An anonymous hacker reportedly uploaded a 1GB file containing over two crore pairs of usernames and passwords of Webkinz World users.

Advertisement
By Jagmeet Singh | Updated: 20 April 2020 18:42 IST
Highlights
  • Webkinz World was a popular title amongst kids
  • The hacker gained access to database using an SQL injection
  • Webkinz World archives inactive user accounts

Webkinz World was launched as an online children’s game back in 2005

A hacker has compromised the credentials of nearly 2.3 crore users of online children's game Webkinz World, according to a report. The game was launched back in April 2005 and was once popular amongst kids, thanks to its gameplay that revolves around stuffed animals. The anonymous hacker has said to have posted the database of the online game on a reputed hacking forum earlier this month. It is also believed that the security breach took place using an SQL injection attack.

The hacker uploaded a 1GB file that included over two crore pairs of usernames and passwords, reports ZDNet. The passwords leaked online, however, were encrypted with the MD5-Crypt algorithm.

It is reported that the vulnerability existed within the Webkinz World database circulated online for some time, and its team did detect the intrusion and patch some loopholes. However, the Canadian company behind the game, Ganz, wasn't able to fix the flaw completely.

Advertisement

“Webkinz has never asked for last names, phone numbers, or addresses and all transactions happen through our eStore, which has its own servers and accounts, which are in no way accessible through Webkinz,” a Ganz spokesperson was quoted as saying in the report. “So even if some was to decrypt a password, there is no information of value on the accounts beyond the game data itself.”

Advertisement

As per the details available on a Webkinz support page, accounts that have been inactive for more than 18 months get archived by the company. It is also claimed to have a practice of removing all information associated with the account “other than the User Name and Password” while archiving accounts.

“Please note that if an account remains inactive for a period of 7 years, Ganz will then delete that account,” the support page reads.

Advertisement

The statement provided by the company to the site highlights that Ganz is currently reviewing the security loopholes to “ensure that a similar attack won't work elsewhere.” It would also force password changes from the backend if it sees that “any player accounts are actually at risk.”

Webkinz World was once next to Disney's Club Penguin in terms of its popularity. However, the game received an upgrade as Webkinz X in 2015.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Xiaomi 17 Ultra Launching Today: All You Need to Know
  2. Realme 16 Pro+ 5G Retail Box Reveals Price in India Weeks Before Launch
  3. OnePlus Nord 6 Visits Certification Website, Could Launch Soon
  4. Rajini Gaang OTT Release Date: Know When and Where to Watch it Online
  1. Why Venus Is the Brightest Morning Star Visible From Earth
  2. Oppo Pad Air 5 Launched With 10,050mAh Battery, 12.1-Inch Display: Price, Specifications
  3. Dracula: A Love Tale Now Available For Streaming Online: What You Need to About its Plot, Cast, and More
  4. Xiaomi 17 Ultra Launching Today: Know Price, Features, Specifications and More
  5. South Korean Startup Innospace Fails on First Orbital Launch Attempt of Hanbit-Nano Rocket
  6. Failing Starlink Satellite Photographed in Orbit Before Fiery Reentry
  7. Russia Patents Rotating Space Station Concept to Generate Artificial Gravity in Orbit
  8. Interstellar Comet 3I/ATLAS Shows Wobbling Jets in Rare Sun-Facing Tail, Surprising Astronomers
  9. Magnetic Control of Lithium Enables Safer, High-Capacity “Dream Battery” Without Explosion Risk
  10. Vritta OTT Release Date Revealed: Know When and Where to Watch it Online
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.