Organization for Transformative Works (OTW) Data Breach Exposes Emails and Passwords

Published: 8 September 2026
Non-profit data breach illustration
Breach Discovery: August 2026Breach Notification: August 2026

In August 2026, the Organization for Transformative Works discovered unauthorized access to its Fanlore wiki, exposing about 145,000 email addresses along with usernames, names, and hashed passwords. Anyone with a Fanlore account may be affected. Affected individuals should immediately change their Fanlore password and any reused passwords elsewhere.

CompanyOrganization for Transformative Works (OTW)
IndustryNon-profit
Data Types ExposedEmail Addresses, Names, Usernames, Passwords (MD5 or PBKDF2 hashes)
People Affected145,000 individuals
Attack MethodUnauthorized Network Access
Regulators NotifiedNot Publicly Disclosed

What Happened in the OTW Fanlore Data Breach?

The Organization for Transformative Works, known as OTW, runs the Fanlore wiki as one of its community projects. In August 2026, OTW discovered that someone had gained unauthorized access to the systems behind this wiki. This discovery triggered the OTW Fanlore data breach investigation that followed.

According to the available details, the unauthorized access to OTW’s network occurred in August 2026. The intruder was able to reach a dataset containing user account information tied to Fanlore. As a result, email addresses, usernames, names, and password data connected to the platform became exposed.

The passwords in the exposed dataset were stored as hashes, using either MD5 or PBKDF2 methods. These are technical processes meant to scramble passwords so they cannot be read directly. However, older hashing methods like MD5 can sometimes be reversed with enough computing effort, so this detail matters for affected users.

After identifying the incident, OTW took the step of submitting the exposed data directly to Have I Been Pwned. This self-reporting approach allowed the breach to be documented and allowed potentially affected individuals to check their exposure status. Because of this, the public record of the OTW Fanlore data breach comes largely from OTW’s own disclosure.

Who was affected?

Anyone who created a user account on the Fanlore wiki could be affected by this incident. Fanlore is a community-driven reference wiki, so its user base likely includes contributors, editors, and registered readers from across the fan community. Because OTW operates internationally, affected individuals may live in the United States and many other countries.

The breach exposed roughly 145,000 unique email addresses. This figure represents the number of distinct accounts tied to the exposed dataset. It is not clear whether this number includes only active accounts or also older, inactive registrations.

There is no indication that this breach involved financial account numbers or government identification numbers. Instead, the exposure centers on account credentials and identifying details tied to wiki participation. Even so, this type of exposure carries real risk, which the sections below explain in more detail.

What Information Was Potentially Exposed?

The OTW Fanlore data breach exposed a defined set of account-related data. This information came from the user database supporting the Fanlore wiki platform. Below is a summary of the categories confirmed as part of this incident.

  • Email addresses
  • Names
  • Usernames
  • Passwords (stored as MD5 or PBKDF2 hashes)

Because email addresses and usernames were exposed together, affected individuals face a heightened phishing risk. Attackers often use this kind of paired data to craft convincing scam messages. For example, a scammer could reference a person’s actual Fanlore username to make a fake email seem legitimate.

In addition, exposed password hashes present a separate concern. If an attacker manages to crack an MD5 hash, they could gain access to the original password. This becomes especially risky if someone reused that password on other websites, since attackers frequently test stolen credentials across multiple platforms.

What is the company doing?

OTW responded to the discovery by investigating the unauthorized access and identifying the scope of the exposed data. The organization then took the proactive step of submitting the compromised records to Have I Been Pwned. This action allowed affected individuals to search their email address and learn whether their information was involved.

Beyond this disclosure, organizations facing similar incidents typically work to close the security gap that allowed access in the first place. This often includes resetting affected passwords and reviewing account security controls. While specific technical remediation steps for OTW have not been publicly detailed beyond the HIBP submission, the self-reporting itself reflects an effort toward transparency with the affected community.

What Should Affected Individuals Do?

Change Your Fanlore Password Immediately

If you have a Fanlore account, change your password right away. This is the single most direct step you can take in response to this breach. Even though passwords were hashed, a cracked hash could still grant someone access to your account.

When choosing a new password, make it long, unique, and unrelated to any password you use elsewhere. A password manager can help generate and store a strong one. This reduces the chance that a future breach on another site could also compromise your Fanlore account.

Update Reused Passwords on Other Accounts

Because password reuse is common, check whether you used your Fanlore password anywhere else. If so, change it on those accounts too. This matters because attackers often try stolen credentials against email providers, banking sites, and social media platforms.

This process, sometimes called credential stuffing defense, can prevent a single leaked password from cascading into multiple compromised accounts. Taking a few minutes now to update reused passwords can meaningfully lower your overall exposure risk.

Watch for Phishing Attempts

Since your email address and username may now be in the hands of bad actors, stay alert for suspicious messages. Phishing emails may look like they come from OTW, Fanlore, or related services. They often try to trick you into clicking a link or entering login details on a fake page.

Before clicking any link in an unexpected email, verify the sender’s address carefully. When in doubt, go directly to the official website rather than using a link from the message. This simple habit can stop most phishing attempts before they succeed.

Monitor Your Identity and Accounts

Although this breach did not expose financial or government ID numbers, it is still wise to monitor your broader digital identity. Check your email account for unfamiliar login activity or password reset requests you did not initiate. This can be an early warning sign of misuse.

In addition, consider reviewing your credit report periodically as a general precaution. While this breach alone may not directly cause financial fraud, exposed emails are sometimes combined with data from other breaches. As a result, ongoing vigilance across your accounts is a smart long-term habit.



Related Data Breaches

Check other recent data breach notifications →