logo

Club Penguin fans breached Disney Confluence server, stole 2.5GB of data

ID: 89652fe8-3ce6-55c9-8d62-efc4a14ea970

STIX ID: report--89652fe8-3ce6-55c9-8d62-efc4a14ea970

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-06-05

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

A threat actor(s) exploited previously exposed credentials to access Disney's Confluence instance, initially extracting Club Penguin PDFs and then a larger 2.5 GB set of internal corporate documents. The leak contains recent (2024) materials including internal API endpoints, credentials (S3 and others), and documentation for internal tools (Helios, CommuniCore), which could enable additional targeted attacks against Disney infrastructure and services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.