ShellCodeX Breach Report
Fanlore Data Breach
fanlore.org
Verified breach
Passwords exposed
Accounts exposed
144,520
Breach date
06 Aug 2026
Added to tracker
19 Aug 2026
Data classes
4
What happened
In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.
Exposed data
Email addresses
Names
Passwords
Usernames
Recommended actions
- Change your Fanlore password immediately, and update it anywhere you reused the same password.
- Enable two-factor authentication on the affected account and on your critical services (email, banking).
- Watch for targeted phishing emails referencing Fanlore โ attackers weaponise breach data quickly.
- Check whether your email address appears in this breach on haveibeenpwned.com.
Am I affected?
Check whether your email address appears in this breach.
Check on HIBP