2024 Roll20 — 12M users, compromised admin account
Data compromised
Full names, email addresses, IP addresses, last 4 of credit cards
Technical writeup
Roll20, the online tabletop RPG platform, suffered a breach in July 2024 when a compromised administrative account was used to access user data. Approximately 12 million records were exposed including full names, email addresses, IP addresses, and the last four digits of credit cards.
Root cause
Compromised administrative account; credential theft