Full Report
In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.
Analysis Summary
# Main Topic
Unauthorized access and data breach of the Fanlore wiki platform, operated by the Organization for Transformative Works (OTW), resulting in the exposure of user credentials and PII.
## Key Points
- In August 2026, OTW identified unauthorized access to the Fanlore wiki backend systems.
- The breach resulted in the compromise of 144,554 unique user records.
- Compromised data includes email addresses, usernames, and passwords.
- Technical analysis of the credential storage revealed a mix of legacy MD5 hashes and more secure PBKDF2 hashes.
- The Organization for Transformative Works self-reported the incident and shared the dataset with Have I Been Pwned (HIBP) on August 19, 2026, to facilitate user notification.
## Threat Actors
- **Attribution:** Unknown. The report does not identify a specific threat group or nation-state actor.
- **Motivation:** Likely financial or data theft, given the extraction of a user credential database.
## TTPs
- **Unauthorized Access:** The actor gained entry to the Fanlore wiki infrastructure.
- **Data Exfiltration:** Extraction of user databases containing Personally Identifiable Information (PII) and hashed credentials.
- **Credential Access:** Accessing stored password hashes (MD5/PBKDF2).
## Affected Systems
- **Platform:** Fanlore wiki (MediaWiki-based platform).
- **Organization:** Organization for Transformative Works (OTW).
- **Scope:** 144.5k unique accounts and associated metadata.
## Mitigations
- **Credential Reset:** Immediate password changes for all Fanlore users.
- **Password Hygiene:** Users are advised to rotate passwords on any other platforms where the same credentials were reused.
- **Multi-Factor Authentication (MFA):** Implementation of two-factor authentication where supported to mitigate the risk of credential stuffing.
- **Password Management:** Use of encrypted password managers to generate unique, high-entropy passwords for separate services.
- **Hash Upgrading:** Deprecation of MD5 in favor of more robust hashing algorithms like PBKDF2 (which was already partially in use).
## Conclusion
The Fanlore breach highlights the ongoing risk to niche community platforms and the dangers of legacy cryptographic standards like MD5. While the use of PBKDF2 for some hashes provides better protection against brute-force attacks, the exposure of 145k email addresses poses a significant risk for targeted phishing and credential stuffing campaigns. Organizations should prioritize migrating all legacy hashes to modern, salted standards and enforcing MFA across administrative and user accounts.
***
# Morning News Roll-up August 19, 2026
## Overview
Today's intelligence focuses on a significant data breach affecting a large wiki community and the proactive steps taken by the affected organization to notify victims through industry-standard disclosure channels.
## Top Stories
### Fanlore Wiki Data Breach
- Summary: The Organization for Transformative Works reported a security incident involving unauthorized access to Fanlore. The breach exposed the data of over 144,000 users, including hashed passwords and email addresses.
- Source: hxxps://www[.]transformativeworks[.]org/fanlore-security-incident/
### HIBP Integrates Fanlore Dataset
- Summary: The "Have I Been Pwned" service has indexed 144,554 unique email addresses from the Fanlore breach, following a self-submission by the OTW to aid in public transparency.
- Source: hxxps://haveibeenpwned[.]com
### Security Advisory: Legacy MD5 Risks
- Summary: The Fanlore incident underscores the persistent presence of MD5 hashes in modern databases and the necessity for platforms to migrate to more secure algorithms like PBKDF2 to prevent offline cracking.
- Source: hxxps://www[.]transformativeworks[.]org/fanlore-security-incident/