Animal Jam 2020 Data Breach

Animal Jam Children's Online Game Breach (2020): 7 Million Young Player Records Including DOB, Home Address & Passwords Exposed

Company · Children’s online gaming and educational entertainment · Online multiplayer game and virtual world for children · USA

Animal Jam Children's Online Game Breach (2020): 7 Million Young Player Records Including DOB, Home Address & Passwords Exposed

Online multiplayer game for children.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach involves data relating to children. We do not confirm the presence of any individual publicly or to third parties. A parent or guardian can check exposure privately below.
Breach Risk Index i
65/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
7.1MRecords
2020Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
AddressPhysical address
MinorsChildren / minors
Classification Tags
Children & FamilyChildrenUsers2020

Breach Summary

WildWorks, the Utah studio behind the children's online game Animal Jam, suffered a data breach in October 2020 that exposed records tied to approximately 46 million accounts, including over 7 million unique email addresses. An attacker posted details of the breach on a hacking forum in November 2020. WildWorks confirmed the incident and identified the breach pathway as direct, though the specific method of intrusion has not been disclosed publicly. The exposed data included usernames, IP addresses, email addresses, and passwords stored as PBKDF2 hashes. For a subset of records, the breach also exposed dates of birth, physical home addresses, and parent names. Because Animal Jam is designed for children aged 7 to 12, and parents create accounts alongside their children, family data was embedded in the platform by design. That structure meant the breach reached beyond individual users to expose household-level information, including details that could be used to physically identify minors. WildWorks reset affected passwords and notified users directly. Where parental email addresses were on file, the company contacted parents as well. No payment card data was involved. A class-action complaint followed, citing failures under the Children's Online Privacy Protection Act (COPPA), the federal law governing data collection from minors. Affected families should treat any reused passwords as compromised and change them across other accounts. The combination of children's birthdates, home addresses, and parent contact details creates meaningful risk of targeted fraud, harassment, or other harm directed at families.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

7.1M records analyzed

About Animal Jam

Animal Jam is an online game for children. Players adopt animal avatars and explore a nature-themed virtual world. WildWorks, a Utah studio, runs the platform. It is designed for children aged 7 to 12 and operates under COPPA, the federal law governing data collection from minors. Parents create accounts alongside their children. That design decision matters for understanding what the breach exposed.

Why They Hold Your Data

Children’s online games collect player accounts, usernames, parental contact information, device data, gameplay activity, and payment-adjacent records tied to youth-oriented virtual worlds.

Recent Developments

Animal Jam continues to operate under WildWorks. The company has maintained the platform through content updates and seasonal events. No major organizational or ownership changes have been widely reported since the 2020 breach.

Data Points Exposed

8 verified field types
Date of Birth High
Email Address
Full Name
Gender
IP Address
Password High
Physical address High
Username

Breach Impact

In November 2020 an attacker posted details of the breach on a hacking forum. WildWorks confirmed it. The company reset passwords and notified users. Where parental email addresses were on file, it contacted parents directly. No payment card data was involved. But the exposed records included children's birth dates, parent email addresses, home addresses, usernames, and IP addresses. The platform's design meant family data was part of the breach. A class-action complaint followed, citing failures under COPPA. The incident is a clear example of the specific obligations that come with building a platform for children. The data of the family comes with the data of the child.

Exploitation & Downstream Threats

• Credential stuffing against reused passwords across other platforms | • Identity verification bypass using name + date of birth combination | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure

Principal Risk Advisory

What this means for a principal

A breach involving minors: identity data on children carries long-tail identity-theft and safeguarding risk. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  2. Reset any reused passwords and enable MFA on email first, then financial accounts.
  3. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Protect Yourself: Limited Disclosure

Check Exposure: Verification Required

Because this breach involves data about minors, we do not confirm whether any individual appears in it to unverified parties. A verified parent, guardian, or the individual can privately check exposure.

We confirm exposure only to the affected individual or their verified parent or guardian.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation