Illustrative image generated with AI
Alleged Condé Nast Database With 32.8 Million User Records Offered for $15,000
Alleged Condé Nast database with 32.8M user records listed for $15,000, exposing emails, names and addresses from Vogue, WIRED and more.
Text generated by artificial intelligence, published without human review. AI transparency
Cybercrime listing claims millions of previously unseen records
A database allegedly containing 32,815,767 unique Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. The listing reportedly appeared on 7 September 2026.
The seller describes the database as the complete collection associated with the earlier WIRED data leak. It purportedly includes approximately 30.5 million records that were not previously released publicly.
Users connected to Vogue, The New Yorker, GQ, Glamour, WIRED, Vanity Fair and other Condé Nast publications may be affected. Condé Nast has not publicly confirmed the breach, the marketplace listing or the authenticity of the full database.
Ransomnews examined a sample of 5,000 records and found that it behaved like genuine consumer account data gathered over many years. Its assessment relied on internal consistency, geographic accuracy and historical account information rather than attempts to access active Condé Nast accounts.
That analysis supports the seller’s claims, but it does not conclusively authenticate all 32.8 million records. Nor does it establish who originally obtained the information.
What the advertised database reportedly contains
Every record is said to contain a unique email address. Additional identity and contact fields are present only in subsets of the collection:
- 31.6% allegedly contain both a first and last name.
- 22.3% include a postal address.
- 17.5% contain gender information.
- 12.6% include a date of birth.
- 2.9% contain a telephone number.
No passwords, password hashes, usernames or payment-card details were identified in the examined material. That limits the immediate risk of direct account takeover, but it does not make the information harmless.
The database’s value lies in correlation. A criminal could filter for records containing a full name, address and date of birth, then combine those attributes with information from other breaches or commercial datasets. Even a partial profile can make a fraudulent message far more convincing.
The seller also advertises a version excluding WIRED records. That collection allegedly contains 30,455,594 entries, implying that approximately 2.36 million records are associated with WIRED.
The figure closely resembles the 2,366,576 WIRED records released publicly in December 2025. This numerical alignment links the new listing to the previous incident, although it does not prove that the marketplace seller is the original attacker.
Possible scenarios include a direct sale by the intruder, resale by an intermediary, or redistribution by someone who obtained the data after the initial compromise.
Sample tests support authenticity but do not provide confirmation
Ransomnews’ examination found that field-completion rates in the 5,000-record sample were within 1.2 percentage points of those advertised by the seller.
The relationships between names and email addresses were also significant. Among records containing complete names, 61.9% used an email address corresponding to the person’s name or initials. When names were randomly exchanged between records, that rate fell to 0.3%.
This sharp reduction suggests that the names and email addresses were linked organically rather than assembled at random.
The sample also passed several temporal and geographic checks. None of the 227 records using Apple Relay, iCloud, Outlook, Me.com or Proton addresses appeared to predate the relevant email services. Among US records, 96.4% of ZIP codes matched the stated state, while 93.5% matched the stated city.
The data contained irregularities commonly found in long-running databases populated through online forms. Examples included placeholder text such as “Select your state,” numeric dropdown values, inconsistent country labels, lower-case names and dates of birth set to 1 January.
Such errors do not prove provenance. They do, however, resemble the untidy structure of real consumer databases more than a uniformly fabricated list.
Account-creation dates ranged from February 1999 through 23 October 2025. New registrations became much less frequent from September 2025 onward, leading Ransomnews to assess that extraction may have occurred over several weeks between September and late October 2025.
That pattern is consistent with the sequence surrounding the earlier WIRED incident. Publicly released WIRED records extended through September 2025, an individual using the name “Lovely” contacted DataBreaches.net in November, and WIRED-related data was published in December 2025.
The new sample also differed from the previously exposed WIRED material. It reportedly had another field structure, contained names and street addresses more frequently, and showed demographic patterns associated with a wider group of Condé Nast publications.
Broken access control remains a possible route of compromise
The actor known as Lovely previously claimed to have stolen more than 40 million Condé Nast records and threatened to publish information connected to additional titles. Earlier technical analysis found that the attacker’s description was compatible with insecure direct object reference, or IDOR, and related broken-access-control weaknesses.
An IDOR flaw occurs when an application accepts an identifier controlled by the user—such as an account, subscription or customer number—and returns the associated object without adequately verifying authorisation.
For example, changing a numerical identifier in an application request could expose another customer’s record if the server checks that the object exists but fails to confirm that the requester may access it. Automated requests can turn that individual exposure into large-scale extraction.
There is no confirmation that IDOR caused the alleged broader Condé Nast compromise. No affected software product, version, endpoint or CVE identifier has been disclosed, and Condé Nast has not issued a public technical explanation.
Consequently, there is no user-installable patch or specific workaround associated with the incident. Any remediation of the suspected application weakness would need to occur within Condé Nast’s systems, including server-side authorisation checks, request monitoring and investigation of account-record access.
The new seller reportedly operates through a recently created forum account with limited visible reputation and offers escrow. That profile could reflect an attempt to secure one private buyer instead of generating attention through another public release.
At $15,000, the asking price is less than one-twentieth of one cent per record. A private sale could therefore provide a buyer with a large fraud dataset while keeping downstream use harder to observe.
Phishing and subscription fraud are the immediate risks
The lack of credentials shifts the threat from direct password compromise toward impersonation, social engineering and data enrichment.
Criminals could create messages that reference a recipient’s name, address and genuine relationship with a specific publication. Likely pretexts include:
- Subscription renewals or expiration warnings
- Failed billing and payment requests
- Refund notifications
- Delivery or address-verification messages
- Gift-subscription communications
- Account-verification prompts
A message mentioning Vogue, GQ, The New Yorker, WIRED or another title may appear credible because the underlying relationship is real. The recipient may therefore be more willing to open a link, provide payment information or enter credentials on a fraudulent website.
Postal addresses appear in more than one-fifth of the alleged records, so abuse is not limited to email. Attackers or fraudulent marketers could also use physical letters, while records containing telephone numbers may support voice calls or SMS campaigns.
The database could additionally be matched against older credential leaks. Although this collection reportedly lacks passwords, identity attributes can help criminals select targets, answer weak verification questions or personalise credential-harvesting pages.
Private circulation complicates detection. The absence of a complete public dump would not mean that the records are no longer available or being exploited.
How users and organisations should respond
People with Condé Nast accounts or subscriptions should be suspicious of unexpected renewal, refund, billing, delivery or verification requests. Rather than following links in a message, they should enter the publisher’s known website address directly and review the account there.
Payment requests should be confirmed using contact information obtained independently from the communication. The same rule applies to physical letters that cite a real publication or subscription.
A password reset is not the primary response to the examined data because no passwords or password hashes were found. Users should nevertheless protect against correlation with other breaches by adopting unique passwords, using a password manager and enabling multi-factor authentication where available.
Condé Nast and its publications should monitor for brand impersonation, fraudulent subscription activity and unusual customer-support requests. Investigation priorities include determining whether the advertised records correspond to active accounts and whether large-scale data extraction can be identified in historical logs.
Affected versions are not applicable because no vulnerable commercial software release has been named. There is also no disclosed CVE or CISA Known Exploited Vulnerabilities catalog entry associated with the alleged incident.
Until Condé Nast provides confirmation or a technical account, the full scale and cause remain unverified. The available sample analysis nevertheless indicates that the listing warrants attention—particularly because millions of records may be sold privately rather than exposed where defenders can examine them.
Sources
This article is an original reworking based on the sources below.
