[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2ixjn50vjae5b":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda4882514e","club-penguin-rewritten-july-2019","Club Penguin Rewritten (July 2019) Data Breach","cprewritten.net","2019-07-27T00:00:00.000Z","2019-07-30T14:05:10.000Z","2026-07-29T11:40:53.262Z","Third party breach","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Flogins-stolen-from-admin-backdoored-club-penguin-rewritten-site\u002F",[14,16,17],"https:\u002F\u002Fclubpenguinmountains.com\u002F2019\u002F07\u002F30\u002Fclub-penguin-rewritten-has-been-breached\u002F","https:\u002F\u002Fbreaches.sencode.co.uk\u002Fbreaches\u002Fclubpenguinrewrittenjul2019",4007909,"known",null,"unknown","Critical",[24,25,26,27],"Email addresses","IP addresses","Passwords","Usernames","\u003Cp>The Club Penguin Rewritten (July 2019) data breach is related to the second major security incident on the Club Penguin Rewritten platform, an independent fan game, which occurred on July 27, 2019. This record is tracked across 4,007,909 affected accounts. Since there is also an older and smaller-scale separate breach on the same platform dating back to January 2018, it is important to limit this record to the July 2019 incident. The two incidents contain similar types of data, but their dates, the number of records, and user impact should be assessed separately.\u003C\u002Fp>\n\u003Cp>The verified data classes are email addresses, IP addresses, usernames, and passwords. Passwords are stored not in plain text but in bcrypt hash form. Bcrypt is a stronger method compared to storing in plain text or weak hashes; however, if a user chooses a short, predictable, or reused password, the risk is not completely eliminated. Since Club Penguin Rewritten is a gaming community that also appeals to children and young users, parents and users need to be more careful about account security.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The email addresses, usernames, and IP addresses included in this record can link real contact information to a player’s identity. A username may be associated with the in-game identity and community profile. An email address can be used for account recovery, notifications, and logging into other platforms. An IP address does not provide a direct physical address; however, it can give approximate clues about the connection region, service provider, or session context. When used together, these fields can make fake game announcements, account security alerts, and community messages more convincing.\u003C\u002Fp>\n\u003Cp>Having passwords in bcrypt hash form directly reduces the risk of plain text passwords. Nevertheless, password reuse is a significant problem. If a user has used the same password for their email account, game account, social media, or other game forums, attackers may try to guess this password or attempt it on other services. The likelihood that children and young users choose simple passwords or use the same password across different games should be taken into account. Therefore, not only the Club Penguin Rewritten account but also other accounts associated with the same email and username should be checked.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The number of verified affected accounts for this record is 4,007,909. The incident date is marked as July 27, 2019. Data classes are limited to email addresses, IP addresses, usernames, and bcrypt password hashes. The previous Club Penguin Rewritten breach from January 2018 should be kept separate from this record; the older incident is associated with approximately 1.7 million accounts and should be considered a separate record. The July 2019 record is the later and larger scale incident.\u003C\u002Fp>\n\u003Cp>This record does not constitute a verified data class for real name, phone number, physical address, date of birth, payment card, bank information, chat messages, or in-game purchase history. Although Club Penguin Rewritten is a fan-made game service, this record only contains verified fields related to account and session ID. The description should not include non-verified fields such as users' photos, real identity documents, or financial information. The correct scope is the risk of email, username, IP address, and bcrypt password hash.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The users at highest risk are those who use the password they use for Club Penguin Rewritten on other accounts as well. This is especially important for young users because the same password may have been repeated on different games, school emails, social media accounts, or accounts used on devices by family members. If the email account is compromised, the password reset links for other accounts can also fall into the hands of an attacker. Therefore, parents and users should prioritize protecting the email account.\u003C\u002Fp>\n\u003Cp>The second risk group consists of players who use their in-game username on different platforms as well. When the same username is repeated on forums, social media profiles, or other games, a profile matching risk arises. Attackers can use this information to prepare messages such as fake moderator messages, in-game gifts, free items, account verification, or security alerts. The IP address can also make this targeting more convincing on a regional level. In gaming communities for children, safe communication habits are also important.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The password used for Club Penguin Rewritten should not be used on any other account. The user or parent should check email, game, social media, and school accounts where the same password may have been used, and set unique and strong passwords for each. Using a password manager makes this process easier. Even if Bcrypt is used, weak or reused passwords can become guessable over time. Reusing an old password with small changes is not secure.\u003C\u002Fp>\n\u003Cp>Two-factor authentication should be enabled on the email account and recent sessions should be checked. Children or teen users should be informed not to click on links in messages that appear to be from the game administrator, moderator, free item, account verification, or security alert. No real game administrator should ever ask for the user's email password, verification code, or other account information. Suspicious messages should be reviewed with a parent or trusted adult.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Gaming communities, especially when it comes to child and teenage users, should not be seen solely as a space for entertainment. Accounts can be linked to other digital identities through email, username, and password. In the long term, a different password should be used for each gaming account, and parental controls and security alerts should be kept on in children's accounts. It is also important for privacy that usernames do not contain personal information and are not unnecessarily repeated across different platforms.\u003C\u002Fp>\n\u003Cp>A strong password storage method alone is not sufficient in terms of platforms. Access permissions, administrator accounts, legacy infrastructure, session logs, and incident reporting processes should be regularly checked. In communities targeting children, user safety and communication security should be a higher priority. From the users' perspective, a permanent strategy involves unique passwords, email account security, caution against suspicious game messages, and regular account checks with parental support.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>A match found in this record indicates that the relevant email address is among the accounts associated with the Club Penguin Rewritten July 2019 data breach. A match does not mean that the user's real name, address, payment information, or chat contents are included in the verified scope of this record. The verified fields are email address, IP address, username, and bcrypt password hash. If the user has used the same password on other accounts, those accounts should be prioritized for changes.\u003C\u002Fp>\n\u003Cp>Parents should check whether children or young users have registered for other games with the same email and username. Suspicious game messages, promises of free items, account verification links, and requests appearing to be from moderators should not be responded to without verification from the official channel. After securing the email account, sessions on game and social media accounts should be reviewed, and unknown links should be removed. Even if this incident is old, its impact may continue due to password reuse.\u003C\u002Fp>","","Club Penguin Rewritten (July 2019) Data Breach (4 Million Reported Records)","Club Penguin Rewritten (July 2019) Data Breach. 4 Million reported records were reported. Reported data: Email addresses, IP addresses, Passwords. Review the…","\u002Fuploads\u002Flogo\u002Fcprewritten_net.webp",false,{"name":35,"sector":36,"country":29,"website":9,"websiteArchiveUrl":37,"websiteStatus":38,"websiteCheckedAt":39},"Club Penguin Rewritten (July 2019)","Online game fan community","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20220428134803\u002Fhttps:\u002F\u002Fcprewritten.net\u002F","archived","2026-07-29T11:30:22.391Z"]