import_contacts

Animal Jam Data Breach Passwords

Furthermore, because the data included parent emails, phishing campaigns skyrocketed. Parents received emails stating: "Your child’s Animal Jam account has been banned for fraud. Click here to verify payment details." Because the scammers knew the parent’s real email address and child’s username from the breach, these phishing attempts were highly convincing.

They patched the third-party server vulnerability that allowed the initial intrusion.

The lawsuit highlighted that WildWorks had been warned by security researchers years prior about their poor password storage but failed to act due to "legacy code" issues. The outcome of the litigation resulted in undisclosed settlement costs, but the reputational damage was permanent.

An analysis of the exposed passwords reveals some concerning trends:

Animal Jam Data Breach Passwords + --> -->