Fanlore Breach: 144K Accounts & Password Hashes Exposed (2026)
In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates . The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed...
Overview
The Organization for Transformative Works (OTW) disclosed in August 2026 that its Fanlore wiki experienced a security breach, compromising 144,520 user accounts. The non-profit organization, best known for running Archive of Our Own (AO3), detected unauthorized access and subsequently self-submitted the stolen data to Have I Been Pwned (HIBP). This incident affects Fanlore users who registered on the wiki platform, which serves as a collaborative archive for fanworks and fan history.
What Was Exposed
The breach exposed four distinct data categories: email addresses, usernames, display names, and password hashes. The passwords were stored using either outdated MD5 hashing or the more robust PBKDF2 algorithm. This distinction matters significantly - MD5 hashes can be cracked in seconds using readily available tools, while PBKDF2 with proper salting makes offline cracking computationally expensive. Unfortunately, OTW has not specified what percentage of accounts used each hashing method, meaning affected users must assume their password may be at risk.
Account Takeover Risks
For users whose passwords were protected only by MD5, the risk of account takeover is immediate. Cybercriminals can decrypt these hashes and pair them with the exposed email addresses to attempt credential stuffing attacks across other platforms. Given that many users reuse passwords, the danger extends far beyond Fanlore itself. Even PBKDF2-hashed passwords face risk if users chose weak or common passwords - the algorithm only slows down cracking, it doesn’t stop it.
The OTW breach also highlights the importance of using unique passwords for every platform. This incident mirrors previous credential dumps that have affected communities built around shared creative interests, where trust in the platform often leads to password reuse.
What to Do Right Now
If you have a Fanlore account, treat your password as compromised immediately:
- Change your Fanlore password as soon as possible
- Change the password on any other website where you used the same credentials
- Enable two-factor authentication where available
- Watch for phishing emails attempting to exploit the breach - OTW will never ask for your password via email
Consider using a password manager to generate and store unique, complex passwords for each account going forward. This single habit would have neutralized most of the risk from this breach.
How to Check If You’re Affected
OTW has confirmed self-submitting the data to Have I Been Pwned, making it easy to verify exposure. Visit haveibeenpwned.com and search your email address. If you appear in the breach list, you will see which email addresses were compromised and can immediately begin securing your accounts.
Given the August 2026 disclosure date, the actual breach may have occurred earlier. Check your email for any OTW notifications and review your account activity for unauthorized changes.
Security Insight
This breach reveals a critical lesson about legacy infrastructure in volunteer-run organizations. Fanlore’s continued use of MD5 hashing suggests password storage practices lag behind modern standards, and the absence of mandatory two-factor authentication further weakened account protection. Non-profits operating community platforms must prioritize security investment just as aggressively as commercial entities - communities built on trust become prime targets precisely because users let their guard down. The OTW’s transparency in self-reporting to HIBP is commendable, but this incident underscores that older wiki software often carries vulnerabilities that newer platforms have already addressed.
Further Reading
Investigate Breaches Safely with NordVPN
Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.
Get NordVPN for ResearchAffiliate link — we may earn a commission at no extra cost to you.
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In January 2026, the automotive research and car-shopping platform Edmunds was listed by the ShinyHunters hacking group as having been breached . Data purportedly obtained in the incident was later published publicly and included 178k unique email addresses, usernames, passwords, IP addresses, phone...
In May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and published the service's database to a public GitHub repository. The incident exposed 64k unique email addresses along with usernames, IP addresses, suppo...
In December 2025, the European Dragonica private server Dragonica Lunaris suffered a data breach. The incident exposed 126k email addresses, usernames, dates of birth and bcrypt password hashes. The service operator confirmed the breach and advised it has since been fixed.
In April 2026, the music trivia platform SongTrivia2 suffered a data breach that was subsequently published to a public hacking forum . The data contained a total of 291k unique email addresses sourced from either Google OAuth logins or accounts created on the site, the latter also containing bcrypt...