← Organization for Transformative Works

2026 Fanlore (OTW) — unauthorized access; HIBP 145k emails + MD5/PBKDF2 password hashes

2026 145.0K records affected Share on X

Data compromised

HIBP/OTW: ~145k unique emails, usernames, names, passwords as MD5 or PBKDF2 hashes; forum summaries also cite tokens and activity metadata

Technical writeup

Verified OTW disclosure with HIBP load — August 2026. The Organization for Transformative Works said it identified unauthorized access to Fanlore and self-submitted exposed account data to Have I Been Pwned. HIBP lists ~145,000 unique emails plus usernames, names, and passwords stored as MD5 or PBKDF2 hashes. Dark Web Informer later observed forum circulation of matching account tables (actor 584) pointing back to the self-reported incident. recordsAffected 145000 from HIBP; companyConfirmed true.

Root cause

OTW identified unauthorized access to Fanlore wiki (Aug 2026) and self-submitted corpus to HIBP

References