Supply chain
⛓ Supply Chain
WildWorks Third-Party Breach (November 2020)
Primary Source ↗Incident Details
Animal Jam Hacked, 46M Records Roam the Dark Web. Animal Jam, just the latest in a string of attacks on gaming apps, has adopted a transparent communications strategy after stolen data turned up on a criminal forum. The company behind the wildly popular kids’ game Animal Jam has announced that hackers stole a menagerie of account records during a breach of a third-party vendor’s server in October — more than 46 million of them, in fact. The company, WildWorks, said that it was unaware that the data had been compromised, until 7 million records turned up on an underground forum used by malicious actors to distribute lifted data, on Nov. 11.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Not disclosed
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2020-11-01 Breach occurred
- 2020-11-12 Publicly disclosed