Club Penguin Rewritten 2018 Data Breach

Club Penguin Rewritten Fan Game Breach (2018): 1.7 Million Young Player Accounts Including Passwords Exposed

Community · Online multiplayer game recreation · Fan-run gaming platform · Global

Club Penguin Rewritten Fan Game Breach (2018): 1.7 Million Young Player Accounts Including Passwords Exposed

Fan-made recreation of Club Penguin game.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach involves data relating to children. We do not confirm the presence of any individual publicly or to third parties. A parent or guardian can check exposure privately below.
Breach Risk Index i
65/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
1.7MRecords
2018Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
MinorsChildren / minors
Classification Tags
Cloud MisconfigurationChildren & FamilyChildren2018

Breach Summary

Club Penguin Rewritten, an unauthorized fan recreation of Disney's Club Penguin game, suffered a data breach in January 2018. The incident exposed roughly 1.7 million unique email addresses tied to player accounts, alongside usernames, IP addresses, and passwords stored as bcrypt hashes.\n\nThe site was an independent project not affiliated with Disney, run by fans on the cprewritten.net domain. When contacted at the time, the team confirmed they were aware of the breach and stated that affected users had been notified. Bcrypt is a strong password-hashing algorithm, which limits the immediate risk of password recovery, but credential reuse across other services remains a concern.\n\nThe user base of Club Penguin Rewritten included a significant share of children under the age of thirteen, since the game was designed for and marketed to young players. That makes the breach particularly sensitive. The combination of email, username, and IP address can support credential stuffing, account takeover at other gaming or social services, and targeted contact attempts. Parents whose children registered at the site should rotate any reused passwords and remain alert to phishing aimed at young account holders.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

1.7M records analyzed

About Club Penguin Rewritten

Club Penguin Rewritten was a fan-run online recreation of Disney's original Club Penguin multiplayer game, operating at cprewritten.net from around 2017 to 2022. The site was an unauthorized recreation produced and maintained by independent fans rather than Disney, and it functioned as a free-to-play web game with player avatars, in-game chat, and persistent accounts. Its user base was global and skewed young, with a substantial share of players under the age of thirteen. At its peak during the pandemic, the site reportedly added tens of thousands of new accounts a day.

Why They Hold Your Data

Fan-run online gaming communities collect user accounts, usernames, emails, passwords, IP addresses, and in-game or community activity tied to multiplayer participation.

Recent Developments

The fan game was shut down in April 2022 after Disney filed a copyright complaint and the City of London Police's Intellectual Property Crime Unit seized the website. Three individuals associated with the project were arrested on suspicion of distributing material infringing copyright. The cprewritten.net domain was placed under police control, and the project's Discord server, which had over 140,000 members, was wiped at the same time. The site has remained offline since. Various other fan recreations have appeared in its absence, but none under the Club Penguin Rewritten name.

Data Points Exposed

4 verified field types
Email Address
IP Address
Password High
Username

Breach Impact

The 2018 incident generated little direct cost to Club Penguin Rewritten as an operation, since the project was an unauthorized fan recreation rather than a licensed business with formal compliance obligations. There was no regulatory action tied to the breach, no public class-action filing, and no settlement. The site continued to operate for four more years before its 2022 takedown by Disney and UK police. The breach's longer-term significance is reputational: it sits alongside a larger 2019 incident at the same site as evidence that fan-run children's gaming platforms typically lacked the moderation, safety, and security investment of licensed equivalents.

Exploitation & Downstream Threats

• Credential stuffing against reused passwords across other platforms | • Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

A breach involving minors: identity data on children carries long-tail identity-theft and safeguarding risk. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Reset any reused passwords and enable MFA on email first, then financial accounts.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Protect Yourself: Limited Disclosure

Check Exposure: Verification Required

Because this breach involves data about minors, we do not confirm whether any individual appears in it to unverified parties. A verified parent, guardian, or the individual can privately check exposure.

We confirm exposure only to the affected individual or their verified parent or guardian.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation