2026 Fanlore (OTW) — unauthorized access; HIBP 145k emails + MD5/PBKDF2 password hashes
Data compromised
HIBP/OTW: ~145k unique emails, usernames, names, passwords as MD5 or PBKDF2 hashes; forum summaries also cite tokens and activity metadata
Technical writeup
Verified OTW disclosure with HIBP load — August 2026. The Organization for Transformative Works said it identified unauthorized access to Fanlore and self-submitted exposed account data to Have I Been Pwned. HIBP lists ~145,000 unique emails plus usernames, names, and passwords stored as MD5 or PBKDF2 hashes. Dark Web Informer later observed forum circulation of matching account tables (actor 584) pointing back to the self-reported incident. recordsAffected 145000 from HIBP; companyConfirmed true.
Root cause
OTW identified unauthorized access to Fanlore wiki (Aug 2026) and self-submitted corpus to HIBP