Skip to content
Cyber Security Firms
ConfirmedNon-profit

Fanlore Data Breach (August 2026)

The Organization for Transformative Works found unauthorized access to the server running its Fanlore wiki on August 6, 2026, exposing 144,520 unique email addresses along with usernames and hashed passwords, according to Have I Been Pwned.

Disclosed Updated
Organization
Fanlore
Country
United States
Incident date
August 6, 2026
Disclosed
August 19, 2026
Records affected
145,000
Attack type
Undisclosed
Status
Confirmed
Data exposed
  • Email addresses
  • Names
  • Passwords
  • Usernames
Timeline
  1. OTW discovers unauthorized access to the server hosting Fanlore at approximately 01:30 UTC, according to its incident statement.
  2. OTW publishes its Fanlore security incident notice describing what the attacker reached.
  3. Have I Been Pwned loads the 144,520 verified records that OTW self-submitted, per the listing.

What Happened

The Organization for Transformative Works discovered unauthorized access to the server hosting its Fanlore wiki at approximately 01:30 UTC on August 6, 2026, according to the nonprofit's own incident statement published on August 13. The statement says an attacker reached Fanlore's files and database, and identifies a MediaWiki extension that contained a security vulnerability. OTW attributed the access to unknown third parties and named no group.

Have I Been Pwned loaded 144,520 unique email addresses from the incident, along with usernames and passwords stored as either MD5 or PBKDF2 hashes, per its entry, and notes that OTW self-submitted the exposed data. According to the OTW statement, passwords were hashed through a one-way process rather than kept in plain text, real names were not collected by the wiki, and IP addresses recorded against edits were also within reach of the attacker.

Per the OTW statement, the attacker likely also holds the full edit history of every Fanlore page, including revisions that had been hidden or deleted. The organization says Archive of Our Own was not affected, and advised anyone who reused a Fanlore password on that site to change it as a precaution. The notice, credited to a volunteer posting as Lute, does not say how long the vulnerable extension was reachable before the discovery.

What Was Exposed

4 classes of data across 144,520 records, per Have I Been Pwned: Fanlore Data Breach: email addresses, names, passwords and usernames.

Email addresses tied to usernames and password hashes let an attacker attempt the same credentials on other services and connect pseudonymous wiki accounts to the real inboxes behind them.

What to Do If You Are Affected

The full sequence, and what to do in what order, is in what to do after a data breach.

What Is Not Known Yet

OTW has not said which MediaWiki extension was vulnerable, how long the attacker had access before the August 6 discovery, or what share of the exposed hashes used the weaker MD5 format. No group has claimed the intrusion.

Sources

  1. Have I Been Pwned: Fanlore Data Breach
  2. Organization for Transformative Works, "Fanlore Security Incident," August 13, 2026
On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →