In August 2026, unauthorized access to the Fanlore wiki exposed approximately 145,000 accounts including email addresses, usernames, names, and hashed passwords.
Loading page…
Loading page…
In August 2026, unauthorized access to the Fanlore wiki exposed approximately 145,000 accounts including email addresses, usernames, names, and hashed passwords.
According to HIBP, the Organization for Transformative Works (OTW) identified unauthorized access to its Fanlore wiki in August 2026. OTW self-reported the incident and submitted the exposed data directly to HIBP.
The breach exposed roughly 145,000 unique email addresses along with usernames, names, and passwords. Reported by HIBP, the passwords were stored as hashes using either MD5 or PBKDF2 algorithms. MD5 hashes are considered weak and may be cracked more easily than PBKDF2.
Anyone with a registered account on the Fanlore wiki at the time of the breach may be affected. Fanlore is a fan-run wiki operated by OTW, the nonprofit behind Archive of Our Own (AO3).