← Roll20

2024 Roll20 — 12M users, compromised admin account

2024 12.0M records affected Share on X

Data compromised

Full names, email addresses, IP addresses, last 4 of credit cards

Technical writeup

Roll20, the online tabletop RPG platform, suffered a breach in July 2024 when a compromised administrative account was used to access user data. Approximately 12 million records were exposed including full names, email addresses, IP addresses, and the last four digits of credit cards.

Root cause

Compromised administrative account; credential theft

References