Roll20 discloses breach of an administrative account exposing user records

Organization
Roll20
Exploit
Hacking
Industry
Gaming

Roll20, a virtual tabletop platform used to run online role-playing games, disclosed on 3 July 2024 that an unauthorized party had gained access to an administrative account on its website. The intrusion started at about 6:30 pm Pacific time on 29 June and access was blocked roughly an hour later.

Within that window the intruder could view and access every user account through Roll20's administrative tooling. The company said the exposed fields were first and last names, email addresses, last known IP addresses and, for members with a stored payment method, the last four digits of a credit card number. Passwords were not exposed, as Roll20 stores them salted and hashed with bcrypt, and full payment details sit with its payment processors rather than in the compromised console.

One user account was modified during the intrusion. Roll20 reversed the change and said it had found no evidence that any of the accessed data was being misused. A spokesperson said the company regretted that the incident happened on its watch and that it had chosen to notify users promptly.

Roll20 put its user base at roughly 12 million but did not say how many people were affected or how many had partial card data exposed. Its post-incident plan restricted administrative account access and narrowed the data those accounts can reach. TechCrunch noted an earlier Roll20 breach that involved more than four million records.

Sources