Security researchers test sites for breaches and notify them about how to patch any vulnerabilities. Neopets has had a breach since August.
Here is some info from the researcher (on Twitter):
Quote:
To address all concerns:
If you have a Neopets account and you are an active user, change your password immediately. Unfortunately, I don't know how long threat actors have had access, but I will let all of you know when it's secured - and then change your password again
Quote:
Update: Neopets is working hard on fixing this. They've already patched 4 or 5 vulnerabilities. There's still quite a bit of work to be done, but great progress is being made and they are being amicable about the situation.
Quote:
Security Researchers are ethical. We do not leak the specifics of our research. We do not dump user data. We do not share PII. We will not give you anything. The only entity that will receive anything is the Enterprise.
If you use the same password on Neopets as other sites:
1) Stop doing that.
2) Change your password on all those other sites (to something different from each other and your Neopets one).