Club Penguin Rewritten Data Breach
Club Penguin Rewritten Fan Game Breach (2018): 1.7 Million Young Player Accounts Including Passwords Exposed
Fan-made recreation of Club Penguin game.
Risk Interpretation
Primary risks include account takeover, password reuse, and harassment. Because the user base may include minors or young users, identity and safety risks are elevated.
Impact & Downstream Threats
The 2018 incident generated little direct cost to Club Penguin Rewritten as an operation, since the project was an unauthorized fan recreation rather than a licensed business with formal compliance obligations. There was no regulatory action tied to the breach, no public class-action filing, and no settlement. The site continued to operate for four more years before its 2022 takedown by Disney and UK police. The breach's longer-term significance is reputational: it sits alongside a larger 2019 i
- Credential stuffing against reused passwords across other platforms
- Targeted phishing campaigns using exposed email addresses
Threat Vectors
Breach Intelligence
Executive Summary
Club Penguin Rewritten, an unauthorized fan recreation of Disney's Club Penguin game, suffered a data breach in January 2018. The incident exposed roughly 1.7 million unique email addresses tied to player accounts, alongside usernames, IP addresses, and passwords stored as bcrypt hashes.\n\nThe site was an independent project not affiliated with Disney, run by fans on the cprewritten.net domain. When contacted at the time, the team confirmed they were aware of the breach and stated that affected users had been notified. Bcrypt is a strong password-hashing algorithm, which limits the immediate risk of password recovery, but credential reuse across other services remains a concern.\n\nThe user base of Club Penguin Rewritten included a significant share of children under the age of thirteen, since the game was designed for and marketed to young players. That makes the breach particularly sensitive. The combination of email, username, and IP address can support credential stuffing, account takeover at other gaming or social services, and targeted contact attempts. Parents whose children registered at the site should rotate any reused passwords and remain alert to phishing aimed at young account holders.
About Club Penguin Rewritten
Club Penguin Rewritten was a fan-run online recreation of Disney's original Club Penguin multiplayer game, operating at cprewritten.net from around 2017 to 2022. The site was an unauthorized recreation produced and maintained by independent fans rather than Disney, and it functioned as a free-to-play web game with player avatars, in-game chat, and persistent accounts. Its user base was global and skewed young, with a substantial share of players under the age of thirteen. At its peak during the pandemic, the site reportedly added tens of thousands of new accounts a day.
Why They Hold Your Data
Fan-run online gaming communities collect user accounts, usernames, emails, passwords, IP addresses, and in-game or community activity tied to multiplayer participation.
Recent Developments
The fan game was shut down in April 2022 after Disney filed a copyright complaint and the City of London Police's Intellectual Property Crime Unit seized the website. Three individuals associated with the project were arrested on suspicion of distributing material infringing copyright. The cprewritten.net domain was placed under police control, and the project's Discord server, which had over 140,000 members, was wiped at the same time. The site has remained offline since. Various other fan recreations have appeared in its absence, but none under the Club Penguin Rewritten name.
Data Points Exposed
Canonical Fields
email_address, ip_address, password, username
Dark Web Verification
- Dataset containing ~1.7M records identified in breach intelligence sources
- Data indexed and searchable across breach notification platforms
- Source: club-penguin-rewritten-2018;Club Penguin Rewritten (January 2018) Data Breach
Recommended Actions
⚠️ Do not assume this is low sensitivity.
Protect Yourself
Check If You’re Affected
Enter your email to check if your data appears in this breach.
Get Free Breach Alerts
Be the first to know when new breaches are disclosed.
High-Risk? Get an Exposure Audit
Full-spectrum exposure audits for executives and public figures.
ObscureIQ Advisory
We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.
- A public-facing individual
- A high-profile executive
- A customer of Club Penguin Rewritten
- Or concerned about credential reuse
Powered by the ObscureIQ Breach Intelligence Database
© 2026 ObscureIQ · All Rights Reserved · Data Licensing
Latest from ObscureIQ
What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.
Sextortion Spam
