CSIDB logo
Threat actor

New World Order

Attribution profile

Type
Insider - Disgruntled
Location
United States of America
Known incidents
0 incidents
First seen
-
Last seen
-
Updated
2026-07-31 01:44
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

New World Order, also known by the nickname Codey, is a threat actor based in the United States of America who operated as a former administrator of the Club Penguin Rewritten online gaming platform. The actor’s background as an insider provided privileged access to the site’s infrastructure, allowing the placement of concealed PHP files that created a backdoor into the live database. This access vector enabled the actor to exfiltrate email addresses, usernames, bcrypt‑hashed passwords, and approximately 2.9 million IP address logs associated with registrations and login activity. The primary target was the Club Penguin Rewritten service, a massively multiplayer online game aimed at children aged six to fourteen, placing the actor within the online gaming sector with a global user base despite the server’s likely U.S. location. Strategic objectives observed in the activity included financial gain through the theft of rare virtual items that can be exchanged for real money, as well as disruption evidenced by attempts to damage records and delete valuable accounts after the breach was detected.

The actor’s tactics, techniques, and procedures centered on exploiting legitimate administrator credentials left after a contentious departure, using custom PHP scripts hidden among benign files to avoid detection while querying the database for sensitive data. No malware families or external tooling were referenced; the threat relied solely on the abused insider privilege and the covertly embedded code to harvest bcrypt password hashes and IP logs, which could later be cracked offline to obtain clear‑text credentials. Attribution information does not indicate any state sponsorship or affiliation with a criminal consortium; the activity appears to be the work of an individual acting alone following a disputed exit from the development team. Notable publicly reported operations linked to this actor include the July 2019 breach that compromised roughly 4,007,909 accounts and an earlier January 2018 incident that exposed about 1.7 million unique email addresses and password hashes, both of which were subsequently traced to the same backdoor mechanism. These incidents illustrate a pattern of insider‑driven data theft targeting a niche gaming community for monetary exploitation and retaliatory disruption.

Incidents

Attributed incidents are available to members.

0 incidents
CSIDB