Critical

Fanlore Breach: 144K Accounts & Password Hashes Exposed (2026)

By Yazoul AI · automated

In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates . The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed...

Overview

The Organization for Transformative Works (OTW) disclosed in August 2026 that its Fanlore wiki experienced a security breach, compromising 144,520 user accounts. The non-profit organization, best known for running Archive of Our Own (AO3), detected unauthorized access and subsequently self-submitted the stolen data to Have I Been Pwned (HIBP). This incident affects Fanlore users who registered on the wiki platform, which serves as a collaborative archive for fanworks and fan history.

What Was Exposed

The breach exposed four distinct data categories: email addresses, usernames, display names, and password hashes. The passwords were stored using either outdated MD5 hashing or the more robust PBKDF2 algorithm. This distinction matters significantly - MD5 hashes can be cracked in seconds using readily available tools, while PBKDF2 with proper salting makes offline cracking computationally expensive. Unfortunately, OTW has not specified what percentage of accounts used each hashing method, meaning affected users must assume their password may be at risk.

Account Takeover Risks

For users whose passwords were protected only by MD5, the risk of account takeover is immediate. Cybercriminals can decrypt these hashes and pair them with the exposed email addresses to attempt credential stuffing attacks across other platforms. Given that many users reuse passwords, the danger extends far beyond Fanlore itself. Even PBKDF2-hashed passwords face risk if users chose weak or common passwords - the algorithm only slows down cracking, it doesn’t stop it.

The OTW breach also highlights the importance of using unique passwords for every platform. This incident mirrors previous credential dumps that have affected communities built around shared creative interests, where trust in the platform often leads to password reuse.

What to Do Right Now

If you have a Fanlore account, treat your password as compromised immediately:

  1. Change your Fanlore password as soon as possible
  2. Change the password on any other website where you used the same credentials
  3. Enable two-factor authentication where available
  4. Watch for phishing emails attempting to exploit the breach - OTW will never ask for your password via email

Consider using a password manager to generate and store unique, complex passwords for each account going forward. This single habit would have neutralized most of the risk from this breach.

How to Check If You’re Affected

OTW has confirmed self-submitting the data to Have I Been Pwned, making it easy to verify exposure. Visit haveibeenpwned.com and search your email address. If you appear in the breach list, you will see which email addresses were compromised and can immediately begin securing your accounts.

Given the August 2026 disclosure date, the actual breach may have occurred earlier. Check your email for any OTW notifications and review your account activity for unauthorized changes.

Security Insight

This breach reveals a critical lesson about legacy infrastructure in volunteer-run organizations. Fanlore’s continued use of MD5 hashing suggests password storage practices lag behind modern standards, and the absence of mandatory two-factor authentication further weakened account protection. Non-profits operating community platforms must prioritize security investment just as aggressively as commercial entities - communities built on trust become prime targets precisely because users let their guard down. The OTW’s transparency in self-reporting to HIBP is commendable, but this incident underscores that older wiki software often carries vulnerabilities that newer platforms have already addressed.

Further Reading

Investigate Breaches Safely with NordVPN

Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.

Get NordVPN for Research

Affiliate link — we may earn a commission at no extra cost to you.

Share:

Never miss a data breach report

Get real-time security alerts delivered to your preferred platform.

Related Breach Reports

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.