Roll20 uses cookies to improve your experience on our site. Cookies enable you to enjoy certain features, social sharing functionality, and tailor message and display ads to your interests on our site and others. They also help us understand how our site is being used. By continuing to use our site, you consent to our use of cookies. Update your cookie preferences .
×

Has Roll20 Been Hacked Again?

As of 7/27/2026, I am beginning to see spam from non-roll20 sources being sent to my roll20 compartmentalized email address. The implication is that roll20 has been hacked and that the hackers have taken user profile information. I strongly suggest that roll20 checks for intrustions and, if verified, send an announcement to all affected users so that they know to change their account logins, email, etc. I did not see any spam after the reported data security incident in 2024 (which I missed), so it may be that there has been another intrusion. However, it's certainly possible that hackers haven't made use of the previous info until now. But, I would still recommend that roll20 check to make sure that there hasn't been a new event. Previous event: Data Security Incident (July 3rd, 2024) FAQ – Roll20 Help Center
Thanks for flagging this, and also for using a compartmentalized address in the first place. Reports like this are exactly the kind of signal we want to hear about, so we appreciate you raising it. To address the direct concern: we have no evidence of any new intrusion or unauthorized access to Roll20 systems. We take reports like this seriously, though, and will be performing a review and audit. That said, there a couple of common ways a unique address can start receiving spam without any breach at all, and it may be useful to walk through them: 1. Alias guessing. If your address is something like <a href="mailto:roll20@yourdomain.com" rel="nofollow">roll20@yourdomain.com</a> on a catch-all domain, spammers routinely send to common brand names at catch-all domains. This is by far the most frequent cause of "my unique address got spam" incidents. Plus-addressing ( <a href="mailto:you+roll20@provider.com" rel="nofollow">you+roll20@provider.com</a> ) is similarly easy to guess. 2. A compromise on the receiving side. This could be in the form of malware or browser extensions with mail access on your side, but also could be a compromised forwarding/alias service can expose addresses in a way that looks like a sender-side leak. 3. A compromised mail hop. Email isn't end-to-end encrypted (except under certain circumstances), so every server that legitimately handles a message in transit (like an alias or forwarding service, a filtering gateway, a mail provider) can see the recipient address. If any one of those is compromised, your address can leak, and from your side it would look identical to a sender-side breach. Alias and forwarding services are the most notable case here, since they hold the full mapping of unique addresses by design. But again, we take things like this very seriously. If you're willing, could you please forward one of the spam messages with full headers to us? I will DM you an email address to forward to, if so. The headers can give hints as to whether this is untargeted dictionary spam or something that warrants deeper investigation. We'll follow up in this thread if our review turns up anything users need to act on. If we ever confirm an incident affecting user data, we will notify affected users directly, as we did in 2024. Sincerely, Mike Todd Roll20 CTO
I have tried to send you a message multiple times. There are major issues with the Roll20 PM functionality: 1. The recaptcha timeout is too short 2. Text was drawing over the formatting controls (Edge/Win11) 3. The recaptcha expired with a red box around it and wouldn't let me re-verify 4. After typing the message, forward the spam w/ headers and hitting send, Roll20 said I was blocked. So, I logged in with Firefox instead of Edge. Anyway - hopefully, you got the PM I sent and you can fix the other above&nbsp; issues.
Here is an example of the other problems I report above. I opened the PM window to you, stretched it downward, and it didn't work very well, as described above.
1785383059
B Simon Smith
Marketplace Creator
Edge is not a supported browser.
OK. Besides the fact that lack of Edge support is a very poor business decision, it doesn't explain the rapid re-Captcha timeouts and site blocking when trying to send a PM.
I said that I would DM you an email address to forward it to, including all headers), and I've done that now. It needs to be done that way (as opposed to you sending it to me via DM here) just so that I can see everything "raw". Apologies for the delay, I was out for GenCon for a little while.
Thanks. Hope you had a great time at GenCon!
Wanted to chime in, I have received 2 spam emails in the last 24 hours also tied to a specific alias used only for Roll20. No evidence beyond these two emails, both coming from the same kind of scam "we have hacked your system" scam. Not sure if it's a fresh hack, since I've had this account and email setup for a long time, so it's possible someone has just purchased a list that includes info from the old compromise. Headers show it coming from modpizza.com of all places, so guessing a compromised account there. Want me to send it in as well?
FatherPrax said: Wanted to chime in, I have received 2 spam emails in the last 24 hours also tied to a specific alias used only for Roll20. No evidence beyond these two emails, both coming from the same kind of scam "we have hacked your system" scam. Not sure if it's a fresh hack, since I've had this account and email setup for a long time, so it's possible someone has just purchased a list that includes info from the old compromise. Headers show it coming from modpizza.com of all places, so guessing a compromised account there. Want me to send it in as well? Yes, please do send that as well. I'll DM you the email address to send to. And as a follow up, an internal audit showed no evidence of any sort of hack or leak. We are now working to investigate whether any leaks in third-party services we utilize (such as SendGrid) might have occurred.