Security

Roll20, an online tabletop role-playing game platform, discloses data breach

Comment

Close-up image of a marbled red 20 sided die on a wet wooden surface outside in the sunlight.
Image Credits: Ester Derksen / Getty Images

The popular online tabletop and role-playing game platform Roll20 announced on Wednesday that it had suffered a data breach, which exposed some users’ personal information.  

In a post published on its official website, Roll20 said that on June 29 it had detected that a “bad actor” gained access to an account on the company’s administrative website for one hour, after which the company “blocked all unauthorized access and ended the network breach.” 

“The bad actor modified one user account, and we promptly reversed those modifications. During this time, the bad actor was able to access and view all user accounts,” the company wrote.

The hacker, according to Roll20, “may have been able to view” users’ personal information, including full name, email address, last-known IP address, and the last four digits of their credit card, if the user had stored a payment method on their account. The company added that the hacker did not have access to passwords or full payment information like home addresses and full credit card numbers.

Roll20 said it is notifying users of the breach. Several users shared screenshots of the email notification on social media. A TechCrunch reporter also received the same notification. 

Roll20 spokesperson Jayme Boucher did not respond to a series of questions from TechCrunch, including how many users in total were affected, how many users had their last four digits of their credit card stolen, how the hacker gained access to the administrative account, and whether the company has any information on who the hacker or hackers were. 

Roll20 says on its website that it has 12 million users and that it’s “the No. 1 choice for D&D online.”

“We truly regret that this incident occurred on our watch. Although we have no evidence that any of the data is being misused, and no passwords or card numbers were exposed, we believe in the importance of being transparent with our users about any potential exposure of their personal information,” Boucher told TechCrunch in an email. “We’re still investigating and don’t have further details to share at this time beyond what we shared in our email notification. We prioritized being as transparent as possible as quickly as possible, and that’s why we notified users today.”

In 2019, TechCrunch reported that a hacker had stolen more than 600 million records from 24 websites, including Roll20. The hacker listed 4 million records from the company at the time.

More TechCrunch

Bumble’s new reporting option arrives at a time when, unfortunately, AI-generated photos on dating apps are common

Bumble users can now report profiles that use AI-generated photos

The concept of Airchat is fun, especially if you’re someone who loves to send voice memos instead of typing out long paragraphs on your phone keyboard.

Talky social app Airchat gets a major overhaul, making it more like an asynchronous Clubhouse

Featured Article

The fall of EV startup Fisker: A comprehensive timeline

Here is a timeline of the events that led fledgling automaker Fisker to file for bankruptcy.

1 hour ago
The fall of EV startup Fisker: A comprehensive timeline

Ahead of these potential competitors comes Openvibe, a simple aggregator for the open social web.

Openvibe combines Mastodon, Bluesky and Nostr into one social app

Welcome to TechCrunch Fintech! Last week was a holiday in the United States, so news was a bit lighter than normal. But there was still fintech-related items to report, including…

Should venture capitalists be held accountable when startups screw up?

Fisker Inc. co-founders Henrik Fisker and his wife, Geeta Gupta-Fisker, are lowering their salaries to $1 in order to keep their failed EV startup’s bankruptcy proceedings funded, as lawyers work…

Henrik Fisker drops salary to $1 to keep Fisker Inc. bankruptcy case alive

After announcing a whopping $20 million seed last year, Unlikely AI founder William Tunstall-Pedoe has kept the budding U.K. foundation model maker’s approach under lock and key. Until now: TechCrunch…

Alexa co-creator gives first glimpse of Unlikely AI’s tech strategy

We’re excited to invite Jesse Pollak to TechCrunch Disrupt 2024 to talk about the future of decentralization.

Jesse Pollak will tell us why Coinbase is launching its own Base blockchain at TechCrunch Disrupt 2024

Infactory is a kind of fact-checking search engine that will be focused exclusively on data at launch.

Humane execs leave company to found AI fact-checking startup

In a first, the Federal Trade Commission is banning an app from serving users under the age of 18. The agency announced on Tuesday that it’s banning NGL, an anonymous…

FTC bans NGL from offering its anonymous social app to minors

When people start navigation on Google Maps, the vehicle’s speed is shown in miles or kilometers, depending on the region.

Google Maps is rolling out speedometer, speed limits on iPhone and CarPlay globally

Design and animation are core to the Duolingo experience, which makes learning a new language or skill more like a game rather than a task to be dreaded.

Duolingo acquires Detroit-based design studio Hobbes

Two of my friends died within the last three years. By some coincidence, both of their birthdays fall in the beginning of July. So, twice this week, Facebook has reminded…

Facebook keeps asking me to say ‘happy birthday’ to dead people

Running a small business means doing more with less. AI agents can help, but building custom agents for specific workflows remains challenging, even with today’s low-code/no-code tools. The idea behind…

With $6M in seed funding, Enso plans to bring AI agents to SMBs

The feature puts Spotify in more direct competition with YouTube as a place where creators can interact with their listeners.

Chasing YouTube, Spotify adds comments to podcasts

A new iOS app called Wayther wants to help you better plan your road trips by giving you real-time road conditions and weather forecasts along your route. Created by indie…

Meet Wayther, an iOS weather forecast app designed specifically for road trips

Evolve has confirmed that the personal data of at least 7.6 million people was accessed during LockBit’s ransomware attack.

Evolve Bank says ransomware gang stole personal data on millions of customers

Etsy has been grappling with an influx of generic “junk” and AI-generated products on its platform. The service revised its seller policy on Tuesday, introducing new labels that clarify whether…

Etsy adds AI-generated item guidelines in new seller policy 

Seae Ventures is acquiring Unseen Capital after the death of founder Kayode Owens in 2021. The combined firm will continue to invest in healthcare for minorities and underserved populations. Owens,…

Seae Ventures acquires Unseen Capital after founder death

Apple released the third developer beta version of iOS 18 on Monday. While there are no major new features like Apple Intelligence in this update, there are some neat design…

With the latest iOS 18 developer beta, Apple makes flashlight UI more fun

A startup called DreamFlare AI is emerging from stealth on Tuesday with the goal of helping content creators make and monetize short-form AI-generated content. The company, co-founded by former Google…

Ex-Googler joins filmmaker to launch DreamFlare, a studio for AI-generated video

Nala, a remittance startup that is now widening its portfolio through a new B2B payments platform, has raised $40 million equity in a rare deal that becomes one of the largest…

Nala to use $40M Series A to build B2B payments platform, scale remittance services

Solo founder Cat Jones took the plunge on setting up a travel business right around the time the pandemic was hitting Europe in March 2020. Fast-forward to summer 2024 and…

Byway is using AI to help travelers slow down and take the scenic route

An adtech business owned by Microsoft is the target of a complaint backed by European privacy advocacy group, noyb — a nonprofit that punches far above its weight when it…

Microsoft-owned adtech Xandr accused of EU privacy breaches

Quora says that Previews works best with chatbots that “excel” at programming, like Claude 3.5 Sonnet, GPT-4o and Google’s Gemini 1.5 Pro.

Quora’s Poe now lets users create and share web apps

For over a decade, real-money gaming companies and fantasy sports startups have marketed themselves as video game companies. But as these businesses face increasing regulatory scrutiny, a coalition of more…

Indian game firms want to distance themselves from fantasy sports

Huffington Post founder Arianna Huffington and OpenAI CEO Sam Altman are throwing their weight behind a new venture, Thrive AI Health, that aims to build AI-powered assistant tech to promote…

OpenAI Startup Fund backs AI healthcare venture with Arianna Huffington

The essential labor of data work, like moderation and annotation, is systematically hidden from those who benefit from the fruits of that labor. A new project puts the lived experiences…

Data workers detail exploitation by tech industry in DAIR report

Hello and welcome back to TechCrunch Space. I hope everyone had a great Independence Day. On to the news!

TechCrunch Space: SpaceX’s big plans for Starship in Florida

Featured Article

Valuations of startups have quietly rebounded to all-time highs. Some investors say the slump is over. 

Generative AI businesses aside, the last couple of years have been relatively difficult for venture-backed companies. Very few startups were able to raise funding at prices that exceeded their previous valuations.   Now, approximately two years after the venture slump began in early 2022, some investors, like IVP general partner Tom…

24 hours ago
Valuations of startups have quietly rebounded to all-time highs. Some investors say the slump is over.