Data breach
Club Penguin Rewritten (January 2018)
- Records
- 1,688,052
- Breach date
- 21 January 2018Estimated
- Added
- 4 March 2025
What was exposed
1 type of data · 3 more reported
- Email addresses1,688,052
- PasswordsReported, not counted
- UsernamesReported, not counted
- IP addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In January 2018, Club Penguin Rewritten, an independent recreation of Disney's Club Penguin game hosted at cprewritten.net, suffered a data breach that exposed records for well over a million of its users. According to our investigation team, the indexed dataset contains 1,688,052 rows, with an estimated breach date of January 21, 2018. Independent breach-monitoring sources, including 9Ghz.com, report that a user announced in early January 2018 that they had obtained roughly 1.69 million records from the site's database by exploiting a vulnerability, and that the data was later released online for anyone to download.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Club Penguin Rewritten was a fan-made revival of Disney's original Club Penguin, which Disney shut down in 2017. Because the game was aimed at children, much of its player base consisted of young users, which made the exposure of account data a particular concern for parents and community members at the time.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, with the total count of matching email addresses still being verified.
Independent breach-monitoring sources, including North IT and 9Ghz.com, additionally report that the exposed records included usernames, IP addresses, and passwords stored as bcrypt hashes. Bcrypt is a password-hashing method that is harder to crack than plain text storage, though not impossible for weak or commonly used passwords.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The most immediate risk from a breach of this kind is account takeover. If a user reused their Club Penguin Rewritten password on email accounts, social media, or other websites, attackers who obtained the leaked records could try those same credentials elsewhere. This technique, known as credential stuffing, works because many people reuse passwords across services.
Exposed email addresses can also be used for phishing. Someone with access to the leaked data could send convincing messages that appear to come from the game or a related service, hoping to trick recipients into revealing more information or clicking malicious links. IP addresses reveal general location and internet provider details, which attackers can use to make phishing messages more believable. For a platform whose users were largely children, the presence of IP addresses and usernames in a public leak raised added worries about unwanted contact, although no specific incidents tied to this leak are documented in the sources reviewed as of September 25, 2026.
What Is Club Penguin Rewritten (January 2018) Doing in Response?
According to North IT, when contacted about the incident, Club Penguin Rewritten said it was aware of the breach and had contacted affected users. Beyond that statement, we found no detailed public notice, remediation report, or regulatory filing from the operator in the sources reviewed as of September 25, 2026. Readers should treat the operator's response as limited in what has been publicly documented.
What Should You Do If You Were Affected?
If you had an account on Club Penguin Rewritten around January 2018, take these steps:
Change your password on any account that still uses the password you used on the site, especially your email account.
Do not reuse passwords across websites. Use a unique password for each service, ideally with a password manager.
Turn on two-factor authentication wherever it is offered, particularly for email and social media.
Be cautious with unexpected emails referencing the game, your account, or a supposed security issue, and avoid clicking links or downloading attachments in them.
Because the leaked passwords were stored as bcrypt hashes, plain-text exposure of your password is not confirmed. Still, treating any affected password as compromised is the safest approach.
