[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fcmx5edt7ogaa":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":27,"seoTitle":28,"seoTitleEn":8,"seoDescription":28,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":4,"isSpamList":31,"isMalware":31,"company":32},"68e3266eda11adda4882515e","club-penguin-rewritten","Club Penguin Rewritten (January 2018) Data Breach","club-penguin-rewritten-january-2018","cprewritten.net","2018-01-21T00:00:00.000Z","2019-04-23T05:05:16.000Z","2026-07-29T11:40:53.262Z","Third party breach","https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fclub-penguin-rewritten-2018",[15],1688176,"known",null,"unknown","Critical",[23,24,25,26],"Email addresses","IP addresses","Passwords","Usernames","\u003Cp>The Club Penguin Rewritten (January 2018) data breach is a security incident that occurred in January 2018 in the online gaming community of Club Penguin Rewritten, created independently of Disney’s original Club Penguin game and aimed at children and young players. The number of affected accounts verified for this record is 1,688,176. In the incident, email addresses, IP addresses, usernames, and password hashes stored with bcrypt were exposed.\u003C\u002Fp>\n\u003Cp>This record should not be confused with the separate Club Penguin Rewritten incident that occurred in July 2019. The scope here is the incident dated January 21, 2018, and it is associated with approximately 1.7 million unique email addresses. Since the game is aimed at children and teenagers, the risk is not limited to password security; when usernames, IP addresses, and email addresses are considered together, a more sensitive picture emerges in terms of targeting children's accounts, fake game notifications, and account takeover attempts.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The verified data classes are email addresses, IP addresses, usernames, and passwords. The password field has been reported in bcrypt hash format; this does not mean that the password is available in a directly readable form. Nevertheless, weak, short, or reused passwords may be tried by attackers. When the email address and username are found together, attackers may try to link the game account with identities on other platforms.\u003C\u002Fp>\n\u003Cp>IP addresses can provide clues about approximate location, internet service provider, and session context. When it comes to child and young player audiences, this data should be handled more carefully. Username, email, and IP information can be used in social engineering attempts involving fake moderator messages, promises of free items, account verification links, or excuses to remove penalties. Therefore, the incident is important not only for a technical password change but also for in-game security awareness.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>This record covers 1,688,176 affected accounts and the incident date is recorded as January 21, 2018. Verified data fields include email address, IP address, username, and bcrypt password hash. It has been reported that platform officials were aware of the incident and that they contacted the affected users. The record belongs to an independent Club Penguin remake service; it should not be interpreted as the original Disney Club Penguin service's own data.\u003C\u002Fp>\n\u003Cp>This record does not classify payment card, physical address, phone number, date of birth, private message content, or real name as verified data. Additionally, this record does not cover the separate Club Penguin Rewritten event that took place in July 2019. Although the two events appear under the same brand name, they should be evaluated with different dates and different scopes. This distinction is important to prevent the perception of duplicate records and to ensure that the user correctly understands which event it matches.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Users at the highest risk are those who have used the same password on their Club Penguin Rewritten account for other games, email, social media, or forum accounts as well. Because game accounts are often managed by children or teenagers, passwords may be chosen simply or repeated in multiple places. For accounts opened with a parent's email address, the risk can extend to the family account as well, since password resets and security notifications are managed through email.\u003C\u002Fp>\n\u003Cp>The familiarity of the username can make it easier for an attacker to impersonate the in-game identity or carry out account recovery fraud. IP address information does not provide the exact address; however, approximate region and provider information can help make targeted messages seem more convincing. Child players may be more vulnerable to promises such as free items, rare accounts, moderator privileges, or ban removal. Therefore, parents and account holders need to take action together.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The user who notices a match in this record should change the password used on their Club Penguin Rewritten account and any other accounts that use the same or a similar password. The email account should be secured as a priority, multi-factor authentication should be enabled, and suspicious sessions should be checked. If the account was used by a child, the parent should also review password reuse on the email account, game accounts, and social media accounts.\u003C\u002Fp>\n\u003Cp>In-game or email account verification messages, free membership offers, item rewards, penalty removals, moderator applications, or security alert messages should not be considered trustworthy directly. The domain name should be checked before opening any links, and if possible, actions should be carried out by going directly to the known address. A person who knows your username and previous game information is not trustworthy. Under no circumstances should verification codes, new passwords, email access, or account recovery information be shared with third parties.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Club Penguin Rewritten incident shows that account security requires special attention in gaming communities where children and young users are present. Parents should ensure that children use unique passwords for their game accounts and manage important accounts with secure email addresses that they control. Using a password manager makes it easier to generate unique passwords for different games and social platforms. If old game accounts are not being used, they should be closed or personal information should be minimized.\u003C\u002Fp>\n\u003Cp>Long-term strategy is not only about technical measures. Children should be clearly informed about in-game fraud, fake moderator messages, promises of free items, and risks of account sharing. If usernames are also used on other platforms, it should not be forgotten that attackers could match profiles. Old leaks containing IP address and email data can make future targeted messages appear more realistic; therefore, suspicious communications should be verified through a separate channel.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The presence of a match in this record indicates that the relevant email address is among the accounts seen in the January 2018 Club Penguin Rewritten data breach. A match does not carry the same meaning as the separate incident in July 2019 and should not be considered as data from the original Disney Club Penguin service. The verified scope of this record is limited to the email address, IP address, username, and bcrypt password hash.\u003C\u002Fp>\n\u003Cp>The user or parent should first end the password repetition, strengthen the email account, and be cautious of fake messages coming with the same username on game accounts. If old game passwords are used on other platforms, they should be changed immediately. If it is a child account, the parent should check the account recovery options, close old accounts, and explain short but clear security rules to the child regarding account sharing and fake reward messages.\u003C\u002Fp>","","Club Penguin Rewritten (January 2018) Data Breach. 1.7 Million reported records were reported. Reported data: Email addresses, IP addresses, Passwords. Review…","\u002Fuploads\u002Flogo\u002Fcprewritten_net.webp",false,{"name":33,"sector":34,"country":28,"website":10,"websiteArchiveUrl":35,"websiteStatus":36,"websiteCheckedAt":37},"Club Penguin Rewritten (January 2018)","Online gaming","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20220428134803\u002Fhttps:\u002F\u002Fcprewritten.net\u002F","archived","2026-07-29T11:30:22.391Z"]