For Neopets ONLY discussion.
Post a reply

Neopets Website Hacked!!

Thu Jul 21, 2022 1:50 am

JellyNeo has reported that apparently basically everything on Neo has been hacked and is up for sale.


Key Takeaway: Don't bother changing your Neo password until Neo says to. And...maybe screenshot anything you feel is necessary?

More seriously: if you use your same username/password combination somewhere else (you shouldn't be anyways, but...) change your password immediately. Just in case.

I've been away from the computer most of the day, so sorry for the delay in passing this info on. To be honest, I'm surprised they haven't taken the site down to prevent accounts from being hacked while they're fixing things.

Sigh. An already frustrating week is now more frustrating.

Re: Neopets Website Hacked!!

Thu Jul 21, 2022 6:57 am

Fabulous.

Re: Neopets Website Hacked!!

Thu Jul 21, 2022 6:18 pm

Pretty much.

JN has updated the post - TNT has now recommended you change your password ASAP. They did not mention that the issue has been fixed, so expect to have to change it again sometime soon...sigh.

Re: Neopets Website Hacked!!

Thu Jul 21, 2022 6:32 pm

Thanks I went ahead and changed my password, and will likely need to do it again soon. My gallery appears to be in tact, so that's something?

Re: Neopets Website Hacked!!

Fri Jul 22, 2022 2:25 am

Since I didn't have an up to date SDB listing, I spent some time last night saving each page of my SDB. I got really fast at the "right click->save page as" and then typing in the number process. :P Also saved my gallery, weapons, and my User Lookup.

I figure, worst case scenario, now I have a bit of Neo saved in case this is what puts the final nail in the coffin. I really wish they'd stop focusing on the metaverse mess and actually focus on fixing the site, but it's clear where the priorities are right now. Sigh.

ETA: They actually put something in the news today about it:
Neopets news wrote:IMPORTANT NEWS: Neopets recently became aware that customer data may have been stolen. We immediately launched an investigation assisted by a leading forensics firm. We are also engaging law enforcement and enhancing the protections for our systems and our user data. It appears that email addresses and passwords used to access Neopets accounts may have been affected. We strongly recommend that you change your Neopets password. If you use the same password on other websites, we recommend that you also change those passwords. As our investigation continues, we will update you as appropriate. We truly appreciate your patience and understanding at this time. Thank you.

I suppose after it showed up in multiple off-site articles...they had to put something in there?

Re: Neopets Website Hacked!!

Fri Jul 22, 2022 11:40 am

First time on the site today, and I got a pop-up with the news. At least TNT is taking this breach seriously, unlike prior ones. My Neopets password has been unique since back when Pickles 's account was hacked and TNT pretended it was use error, but I'll change it now. To what, I've no idea....

Re: Neopets Website Hacked!!

Fri Jul 22, 2022 7:21 pm

I am glad they're taking it more seriously now, as well. The first day, it seemed like all the info about it was only off-site. Looks like the pop-up is the same message from the news.

I don't remember them thinking me being hacked was user error, but it was years ago now. Maybe they said something about making sure to change my password regularly? I don't know. I could look it up, but that's more time than I have right now. At any rate, I was clearly hacked somehow, they actually froze my account fairly quickly and then worked with me to get everything back to the way it was before. I had pretty up to date records of what all I had at the time, as well as plenty of ways to prove it was me requesting my account back. There was only one thing they really couldn't "fix" per say, so there's that.

I change my passwords regularly and have a list of all my previously used passwords just so I don't reuse them....and I definitely don't use my Neo password for anything else.

Re: Neopets Website Hacked!!

Fri Jul 22, 2022 8:24 pm

I had the big banner announcement today as well. My passwords are generally unique to every site I visit. That said, I do a terrible job of documenting what I have bought/earned/"own" on Neopets.

I lost access to my original side account (my poor pets I transferred to make room on my primary account are trapped and starving). I know the password, but cannot remember the fake birthday I used. Worse, the server for the throwaway email I used is long-since gone defunct, so I cannot get in. Ah well. It is "just" 3 pets. One of whom I really liked the pet's name.

Re: Neopets Website Hacked!!

Sat Jul 23, 2022 1:53 am

Blue, I think there was a workaround that takes some time, but now I can't remember. Maybe your NF can see your age change, which eventually reveals your birthday if you check every day? Or you can try a few fake birthdays each day, until you finally get the correct one (spacing the guesses out keeps you from being locked out, maybe.)? Pickles, do you remember?

Re: Neopets Website Hacked!!

Sat Jul 23, 2022 3:25 am

I used to be really good at documenting, but not so much anymore.

If you are NFs with the side, yes, you can see the age change, if it's visible to NFs. I actually helped a friend get back into her account that way once. I would not recommend trying to guess multiple times, though - I'm not sure what the rules are on that.

Re: Neopets Website Hacked!!

Sat Jul 23, 2022 7:53 pm

Unfortunately, I did not friend myself on that account, so no way to watch for when the age changes. Ah well.

Re: Neopets Website Hacked!!

Mon Aug 01, 2022 10:26 pm

Aaaaaand now they're forcing a password reset.

...but it sends a link to your email and so far I've had no success in actually receiving the email. It no longer accepts the password I reset to last week, either. I've had trouble receiving the automated emails before, but I do receive ones from support. So...here's hoping? I get the feeling I'm going to be putting in a ticket after dinner.

Even if you can get it to let you reset, people have been commenting that the reset password is not accepted. So...this could be a mess.

ETA: Went ahead and put in a ticket. I'm kinda miffed that they chose THIS method of forcing everyone to reset. Here I was, looking forward to playing some this evening after having worked my tail off all day, and now this. Guessing I'll be locked out of Neo for a few days, with how many tickets they probably have to go through. Sigh. They'd better get this straightened out before my Premium is due for renewal.

Re: Neopets Website Hacked!!

Tue Aug 02, 2022 4:20 am

Sorry, Pickles. It took a couple of errors for the message to go through for me, but then it went well.

I'm assuming you have Neopets in your safe senders list. Hopefully they get it fixed soon.

Re: Neopets Website Hacked!!

Tue Aug 02, 2022 6:11 am

Yep. My current password (new a couple of weeks ago) is not working.

Had to click on "forgot password" to get the "you're forced to reset" box which required clicking the "send" button twice. Not sure how long it should take to get the email, though. Have not seen it come in for "a while." According to the box, "If you do not receive an email within the hour, please contact Customer Support." I'll be in bed within the hour...

...also do not plan to sit and refresh my email for the next hour, either.


ETA - Still no email after ~30 minutes...

Re: Neopets Website Hacked!!

Tue Aug 02, 2022 5:24 pm

I have not heard back from my ticket yet, nor have I been able to get into my account.

I attempted the password reset thing again later, but still didn't get the email. No surprise there. When BLP set up his account, we had used my email as the "parental consent" email, and never got the email, so he ended up having to abandon that initial account and create a new one (there was no way to put in a different email for the parental option at that point). We used a different email (Mr. P's, I think), and had no trouble.

I have the neopets support email as a "contact" which is, as far as I know, the only way to whitelist it, but...that's never made a difference. Like I mentioned before, I've had no trouble getting responses to tickets (and have in recent months when I put in one about Island Builders issues, as well as feedback on Faerie's Hope, so I shouldn't have trouble with whatever response they might (hopefully) give.

I know my first response after this should be to change my email address. Believe me, I will. Despite having used this email for at least 10 years with this account.

I'm hoping I'll have access again on the sooner than later side, but I have very little hope about that. So far, no one is reporting having heard back from their tickets from yesterday. It's going to be a mess. This was probably the stupidest thing they could've done. I mean, I understand forcing a password reset, but they clearly didn't think through whether or not automated emails would go through to everyone. I think my email provider blocks the ones that "appear to be automated" or something. I have no idea. Maybe I'll be back in by my Neo "birthday"? HAH!

Sorry, I'm feeling pretty bummed about this. I really had worked my tail off yesterday during the day, with the hopes of enjoying some time in the evening on Neo. I ended up going to a TKD class instead. I definitely hit the wavemaster a lot harder than I normally would, despite being physically exhausted already.
Post a reply