Fanlore Security Incident

On August 6, 2026, at approximately 01:30 UTC, the OTW discovered unauthorized access to the server hosting Fanlore by unknown third parties. Additionally, the third party leveraged Discord permission vulnerabilities to post spam on the official Fanlore Discord server.

If you have a Fanlore account, find further information below about what happened and what next steps you might need to take.

What Happened

An attacker gained access to Fanlore’s files and database. AO3 was not affected. Immediately after this was discovered, we took the site offline to begin investigation. Concurrently, the attacker utilized permission vulnerabilities to post messages on the official Fanlore Discord, advertising a download of the database. At this time, we have found no evidence that AO3 was directly affected. However, if you use the same password on Fanlore and AO3, then we strongly encourage you to immediately change your AO3 password.

What Was Exposed

The Fanlore database contains account information that may include your email address, your password hash, and the IP addresses recorded alongside your edits. The wiki does not collect real names, so none were exposed.

Fanlore passwords are hashed (meaning they are not stored in plain text, but as a scrambled series of characters). This scramble is created by a one-way process which is not visible even to OTW volunteers –⁠ we never see your actual password. Likewise, the attacker may have been able to access this password hash, but not your actual password. However, we recommend that you still treat your password as compromised.

The Fanlore database also contains the full edit history of every page, including revisions that were later hidden or deleted. Hiding a revision on a wiki removes it from public view but does not remove it from the database. Therefore, the attacker likely also has access to the full edit history of every page, including hidden or deleted revisions.

We have found no evidence that the attacker used any of this data so far. However as evidenced by their actions on the official Fanlore Discord, they are willing to provide the database file as a download.

What We Have Done

After immediately shutting down access to Fanlore, we investigated the method of compromise and the level of access that the attacker attained. We determined that the exploit in question only gave the attacker access to the web server user on the Fanlore server, which only provided access to the Fanlore MediaWiki install and database. The Fanlore infrastructure is isolated from the rest of the OTW infrastructure, and there is no evidence that the compromise extended beyond Fanlore.

We have rotated any application credentials or secrets that were exposed to the attacker, rolled back the damage caused by the attacker, and reset login sessions. We identified and removed the MediaWiki extension that contained the security vulnerability that allowed this attack. Fanlore is now back online. You will be asked to log in again next time you edit Fanlore.

What You Should Do

  1. Change your Fanlore password now. You can do this yourself on the Password Reset page.
  2. If you used your Fanlore password on any other site, change it on those sites as well.
  3. Watch out for any suspicious messages referring to Fanlore or your account. The process to change your password is initiated by you on Fanlore directly.

In general, we always recommend that you follow internet safety best practices, including:

  • Regularly checking haveibeenpwned.com to see if your emails, passwords, or other information has been exposed in data breaches or whether your passwords have appeared in known data breaches.
  • Change your passwords for any breached websites and any accounts on other sites where you may have used the same password.
  • Set a unique, secure password for each and every one of your accounts on all platforms.
  • Use a password manager. This will help you to set unique, secure passwords for each of your accounts without worrying about forgetting them. Many browsers have a free, built-in password manager if you would prefer to avoid third-party software.

Please contact Fanlore directly using their contact form if you have any questions.

Announcement, Fanlore

Comments are closed.