Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →4chan later confirmed that an attacker broke into a server and stole database tables and much of the site’s source code, but early reports that the stolen material identified longtime administrators were not independently verified. The breach was real according to 4chan’s account; the alleged identity leak remained a claim, not an established finding.
What 4chan confirmed about the breach
In an April 26, 2025 post, 4chan said an attacker gained access to a server on April 14 through an outdated software package and a “bogus PDF upload.” The operator said the intruder reached the server, database and administrative dashboard, then spent several hours exfiltrating database tables and much of 4chan’s source code. Moderators noticed vandalism after the download, and the site said it halted its servers. This is 4chan’s account of the incident, not an independent forensic report. 4chan’s April 26 statement
The operator described the damage as “catastrophic” and attributed the vulnerability to delayed updates, a shortage of skilled developer time and limited resources. Those are 4chan’s explanations for how the incident occurred, not independently established findings.
Were 4chan admins and moderators doxxed?
Contemporaneous reports described alleged screenshots of backend systems and a list of administrator and moderator usernames and email addresses posted to rival forum Soyjak.party. WIRED reported that users subsequently circulated alleged doxes containing photographs and personal information. But WIRED said it could not confirm the data was legitimate, and Reuters also reported that it could not immediately confirm the incident details or who was responsible. Neither report authenticated the purported identities. WIRED’s April 15 report; Reuters reporting via Investing.com, April 15
#1 Best Overall
Flashpoint director of analysis and research Ian Gray told WIRED: “The content leaked, if genuine, would remove some of the anonymity from 4chan administrators, moderators, and janitors.” Gray also noted that some users may have registered email addresses years earlier, when they were less concerned about operational security. Both observations were conditional on the material being genuine; they were not forensic confirmation that particular people had been identified.
UC Riverside computer science and engineering professor Emiliano De Cristofaro warned that users exposed as moderators could face targeting because 4chan users traditionally dislike moderators. That too described a possible consequence, not evidence that any specific moderator was exposed.
What the reports do not establish
- They do not establish that every name on the circulated lists was authentic or that any particular administrator’s identity was definitively exposed.
- They do not establish that ordinary users’ identities, IP addresses or account details were among the stolen material. WIRED reported that 4chan collected information such as IP addresses, but that general fact does not show that this breach exposed specific users’ IPs.
- They do not establish the full contents or scope of the stolen database, or a confirmed count of affected people or records.
The key distinction is between what 4chan confirmed—intrusion and exfiltration—and what leaked screenshots and lists allegedly showed. The available contemporaneous reporting did not verify the latter.
How 4chan said it responded
In its April 26, 2025 post, 4chan said its development team replaced the breached server and updated its operating system and code. It temporarily disabled PDF uploads on boards that supported them. The operator also said the Flash board would not return because it saw no realistic way to prevent similar exploits using SWF files, and that it was bringing on additional volunteer developers. 4chan’s recovery account
Recovery reports from that period are historical, not a description of the site’s current status. On April 27, TechCrunch reported that the site was partly back online after nearly two weeks: its status page showed boards and the front page available, while posting, images and thumbnails were still not working. TechCrunch’s April 27 snapshot
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Ofcom’s later investigation is separate from the hack
Ofcom’s official page records an investigation into 4chan Community Support LLC opened June 10, 2025, and closed March 19, 2026. The regulator describes findings and enforcement concerning UK Online Safety Act duties, including illegal-content risk assessment, terms-of-service provisions and age assurance. That regulatory action concerns the service’s compliance; it is not evidence about the 2025 attacker, breach mechanics or alleged identity leak. Ofcom’s investigation page, updated through April 21, 2026
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

