After Zynga's Sept. 2019 data breach, which affected ~172M users, 2 plaintiffs have filed a suit against the company for “failure to reasonably safeguard” info
Nicole Carpenter / Polygon :
Context & Ripple Effects
The lawsuit closes a loop that opened in October 2019, when a hacker claimed to have breached Zynga and stolen Words with Friends player data while the company was still notifying users without disclosing the scale. By December, Have I Been Pwned put the number at 170M emails with usernames and hashed passwords, and this filing converts that disclosure record into a legal claim of unreasonable safeguarding.
The suit also lands in a live litigation environment: weeks earlier, Facebook agreed to improve its security procedures to settle a class action over its own 29M-user breach, giving plaintiffs and courts a recent template for how breach claims against consumer platforms get resolved.
First-order effects
- Zynga now faces litigation costs and potential damages exposure on top of the reputational hit from a breach affecting roughly 172M users, while the two plaintiffs seek redress for exposed credentials.
- Affected Words with Friends players gain a formal vehicle — the class action — to pursue compensation rather than relying only on Zynga's password-reset notifications.
Second-order effects
- Facebook's February 2020 settlement, which traded improved security procedures for resolution of its 29M-user breach suit, gives both sides a pricing benchmark for what a Zynga settlement or judgment might cost.
- Other mobile game publishers holding large credential databases face pressure to harden storage and disclosure practices before they become the next named defendant in a copycat filing.
Third-order effects
- If breach suits keep following the Facebook-settlement pattern, consumer-data litigation becomes a recurring cost line for game platforms, pushing 'reasonable safeguards' from a best practice toward a de facto legal standard enforced through class actions.
- The case adds to Zynga's courtroom docket alongside its earlier IPO-fraud litigation, reinforcing a structure where large consumer-data holders face standing legal exposure independent of any single incident.
The trend: Consumer platform breaches are increasingly resolved not by regulator fines but by private class actions, with each large settlement setting the template for the next plaintiff's filing.