Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

Condé Nast: 32.8M user records for sale, sample verified

Ransomnews Research TeamBy Ransomnews Research TeamSeptember 7, 2026Updated:September 7, 2026No Comments14 Mins Read136 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
32.8 million Condé Nast user records for sale: bar chart of what the records contain, email in every row, names in 32%, postal addresses in 22%, gender 18%, date of birth 13%, phone 2.9%
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

A database of 32,815,767 Condé Nast user records went on sale on a Russian-language hacker forum on 7 September 2026 for $15,000, offered as the full set behind December’s WIRED leak. Ransomnews tested the 5,000-row sample: it is genuine Condé Nast account data, captured in September and October 2025, and the 30.5 million non-WIRED records have not surfaced publicly before. Condé Nast has never commented on the breach.

// KEY FACTS

Victim
Condé Nast · Media and publishing (Vogue, The New Yorker, GQ, Glamour, WIRED and other titles) · United States (global userbase)
Timeline
Attack: Data captured September to late October 2025, on the evidence of the sample  ·  Disclosed: 2026-09-07
Data claimed
claimed 32,815,767 records, one per email address, 14 fields; 30,455,594 without the WIRED subset · Email address in every row; first and last name in 31.6%, postal address in 22.3%, gender in 17.5%, date of birth in 12.6%, phone number in 2.9%. No passwords, usernames or payment data
Ransom status
For sale by an unnamed account on a Russian-language hacker forum that claims to be the December 2025 WIRED leaker (reported as Lovely): $15,000 blitz price, escrow offered, described as a one-time sale that has never been sold before
Verification
Ransomnews analysed the seller's 5,000-row sample. Field fill rates match the seller's own totals to within 1.2 percentage points; 61.9% of rows with a full name carry that name in the email address, against 0.3% when names are shuffled; no email provider appears on an account dated before that provider existed; 96.4% of US zip codes agree with the stated state. The full row count and the seller's identity are not independently verified. Condé Nast has been asked for comment.

A note on what we are publishing. The sample is the personal data of real people. We reproduce none of it. Every figure below is an aggregate: counts, match rates, date ranges and distributions, never a record. We do not link the sample or name the forum, we have removed the seller’s details and the download links from the screenshot, and we did not test any address against a live Condé Nast account.

Listing on a Russian-language hacker forum titled 33M users USA Condé Nast Database, offering 32,815,767 records for a ,000 blitz price; seller details and sample download links removed
The listing as posted on a Russian-language hacker forum on 7 September 2026. Seller details and the sample download links have been removed.

What is being sold

The listing is titled “[33M users – USA] Condé Nast Database [UNTOUCHED, PRIVATE]” and was posted by an account which, according to its profile, registered on 5 September 2026 with a paid membership and has one post and no reputation. In line with our policy, we are not publishing the handle. It offers 32,815,767 records, each with a unique email address, and gives field counts for the rest: 10,367,773 records with a first and last name, 7,317,721 with a postal address, 5,750,346 with a gender, 4,135,784 with a birthday and 966,388 with a phone number. The price is a $15,000 “blitz”, with escrow offered.

Two lines in the post matter more than the numbers. The seller writes that the database “comes with the same database but with WIRED.com records removed because we leaked the WIRED.com database before (subset of this database)”, and that the version without WIRED has 30,455,594 lines. That is a direct claim to be the actor behind the December 2025 WIRED leak, and it is checkable arithmetic: 32,815,767 minus 30,455,594 leaves 2,360,173 WIRED records. The WIRED file published on 20 December 2025 held 2,366,576 records, according to BleepingComputer. The two figures differ by 0.27%.

The sample is a 5,000-row CSV with fourteen columns: an account ID, a creation date, email, phone, gender, first name, last name, birthday, two address lines, city, zip code, state and country. There are no passwords, no password hashes, no usernames and no payment data anywhere in the schema.

How we verified the sample

Nothing in this file can be checked against a live system without touching other people’s accounts, so every test is internal: does the data behave like a real consumer database, and does it behave like Condé Nast’s? Four tests carry most of the weight.

First, the seller’s own statistics. If the sample is a random draw from the file the seller counted, its field fill rates should match the shares in the listing. They do: 31.7% of sample rows carry a first name against 31.6% claimed, 22.2% carry a street address against 22.3%, 12.1% a birthday against 12.6%, 16.4% a gender against 17.5%, 3.5% a phone number against 2.9%. The rows are in no sort order. That is a random sample of the file the seller described, not a curated showcase.

Second, the names belong to the email addresses. Among the 1,558 rows with a full name, 61.9% have that name, or an initial-plus-surname form of it, inside the email address. When we shuffled the names between rows and ran the same test, the match rate fell to 0.3%. Generated data does not produce that correlation; only records where the same person typed both fields do.

Third, time. Every email provider has a launch date, and an account cannot have been registered with an address that did not exist yet. The sample has 88 Apple private-relay addresses, 67 iCloud, 30 outlook.com, 39 me.com and 3 Proton addresses. None of the 227 was created before its provider launched. The earliest Apple relay account dates from October 2020; the service began in September 2019.

Fourth, geography. Of the 1,230 US rows that carry both a zip code and a state, 96.4% agree, and 93.5% of zip codes agree with the stated city. The mismatches are the useful part. One state field holds the literal text “Select your state”, another holds “37”, the index of a dropdown option rather than its label, others read “California”, “mi.” or “NEWYORK”. Those are the fingerprints of web forms filled in by people over two decades. Nobody fabricating a database puts them in.

CheckResultWhat it means
Fill rates vs seller’s totalsWithin 1.2 points on all five fieldsRandom sample of the described file
Name found in email address61.9%, vs 0.3% shuffledNames and emails belong together
Provider launch dates0 violations in 227 accountsCreation dates are real
Zip code vs state (US)96.4% match, 1,186 of 1,230Addresses are real; errors are human
Account creation dates9 February 1999 to 23 October 2025Dates the capture
Stated gender77% female (633 F, 186 M)Fits Vogue, Glamour and Allure, not WIRED
Passwords or payment dataNoneNo credential exposure in this file
Ransomnews Research Team analysis of the 5,000-row sample, aggregates only, 7 September 2026.
Nine rows from the seller's sample of the Condé Nast database with names, emails, streets and zip codes masked, showing creation dates from 2001 to 2025, a state field reading Select your state, a state field holding 37, a city typed as newyork, and two Sign in with Apple relay addresses
Nine rows from the seller’s sample, masked field by field. The amber values are the web-form artefacts: a default option stored as a value, a dropdown index, a city typed without a space. The green addresses are Sign in with Apple relays, which did not exist before September 2019.

The rest of the file is messy in the way a 26-year-old consumer database is messy. A fifth of the birthdays fall on 1 January, the signature of a form that asked for a year. Three people are recorded with ages over 100. Twenty-two email addresses are test or placeholder accounts. 283 first names are entirely lower case. The country field uses both “UK” and “GB”. Gmail accounts for 45% of addresses, Yahoo 13%, Hotmail 8%, AOL 4%, with a long tail of 772 domains that includes legacy regional US cable and telephone providers. Where a country is stated, 82% of rows say United States, which matches the listing’s “USA” label and Condé Nast’s home market.

Is this the same data as the WIRED leak?

It is the same breach and a different, much larger slice of it. The WIRED file was leaked on 20 December 2025 by an actor using the handle Lovely, who had contacted DataBreaches.net a month earlier posing as a researcher. Lovely claimed six vulnerabilities in Condé Nast’s account system that allowed any account’s details to be viewed and its email and password changed, and said they had “downloaded all 33 million user’s information”, as DataBreaches.net reported. On the forums, the actor threatened to release “40+ million” further records from The New Yorker, Vogue, Vanity Fair, Glamour and other titles over the following weeks. SecurityWeek’s reading of the technical claims was insecure direct object reference and broken access control flaws.

Three things tie the new listing to that episode. The row count, 32.8 million, is the “33 million” Lovely described. The implied WIRED subset matches the leaked WIRED file to within 0.27%. And the sample is not simply the public WIRED dump resold under a new label: the WIRED file had names on 12% of records and addresses on 8%, this sample has 32% and 22%; the WIRED file carried display usernames, this schema has none; and the stated gender in this sample runs 77% female, the opposite of WIRED’s readership and exactly what a database dominated by Vogue, Glamour, Allure and Bon Appétit registrations should look like.

// Free tool

How does your own site score?

Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

What we cannot prove is that the seller is Lovely. The handle, the claim and the numbers are consistent with it; a buyer or an associate holding the same file would look identical from the outside. The listing’s “never sold before” is the seller’s word.

When the data was taken

The creation dates put a clock on the intrusion. Accounts in the sample were registered between 9 February 1999 and 23 October 2025. Through the first eight months of 2025 the sample holds 20 to 36 new accounts per month; September has 8 and the first 23 days of October have 4. Condé Nast did not stop acquiring readers in September 2025, so the shortfall is the extraction itself: a harvest that ran for weeks, picking up new accounts only partially as it went, and stopped in the last days of October. That window sits after the WIRED file’s own last record on 9 September 2025, and before Lovely’s first message to DataBreaches.net on 22 November. Whoever pulled this file had access to Condé Nast’s account system across September and October 2025 and, by the actor’s own account, it then took a further month to persuade the company to fix the flaws.

Who is selling it

The forum is one of the established Russian-language cybercrime markets, fee-gated and closed to casual visitors, and a listing there reaches a smaller and more professional audience than the English-language leak sites where the WIRED file was given away for forum credits. The seller’s account is two days old, paid for its membership, has a single post and no reputation, and is offering escrow, which on that forum means the buyer’s money is held by the administration until the goods are checked. That is the profile of someone who wants one quiet sale to a buyer with a use for 32 million profiled email addresses, not attention.

The price tells the same story. Fifteen thousand dollars for 32.8 million records is under a twentieth of a cent per record. The value is not in any one row; it is in a fifth of them carrying a name, a street address and a zip code, a filterable gender field, and subscription histories to some of the most affluent readerships in American publishing.

What Condé Nast readers should do

Start with what is not in the file. There are no passwords or hashes, so this data alone cannot be used to log into an account, and a password reset is not the urgent step it would be after a credential breach. The risk is targeted mail.

  • Expect subscription phishing. An email address next to a real name, a home address and the magazine it belongs to is enough to write a convincing renewal notice, a billing problem or a gift offer from Vogue, The New Yorker or GQ. Reach the publisher’s site directly rather than through a link.
  • Treat physical mail with the same suspicion. A fifth of the records carry a full postal address. Fraudulent “your subscription has lapsed” letters are cheaper than ever to target.
  • Check the address, not the account. If the email in this file is one you reuse elsewhere, the reuse is the exposure. Our StealerCheck tool shows whether an address has surfaced in stealer logs, a materially worse category of exposure than a marketing profile.
  • If you had a WIRED account, this changes little. Those records were already public in December. The new exposure is for readers of every other Condé Nast title.

What this means

Nine months after its account system was copied, Condé Nast has issued no public statement. It did not answer SecurityWeek’s questions in December, and the only public word from inside the group came from Ars Technica, which Condé Nast owns and which said its own separate stack was unaffected. We found nothing since. WIRED’s 2.3 million records were added to Have I Been Pwned. The other 30.5 million people in this file have had no equivalent, because the file was never dumped. It was held, and now it is priced.

That is the pattern to expect more of. An actor who leaks a small brand-name slice for free establishes that the haul is real, then sells the bulk quietly where the buyers are. The public sees the leak; the market sees the sale. For the reader whose Glamour subscription from 2014 is in this file, the difference is academic.

We approached this listing the way we approach every one on Ransomtracker: assume the seller is exaggerating, then test what they handed over. The sample held up on every test we could run without touching a live account. We have contacted Condé Nast for comment, including whether the flaws Lovely described were closed and whether affected readers outside WIRED were ever notified, and will update this article with any response. Press contact for this piece is [email protected].

Frequently asked questions

Is the Condé Nast database for sale real?

The sample is. Ransomnews tested the seller’s 5,000-row sample and it behaves like genuine Condé Nast account data on every internal test: fill rates match the seller’s totals, names match email addresses, no account predates its email provider, and 96% of US zip codes agree with the stated state. The full 32.8 million-row count is the seller’s claim.

Were Condé Nast passwords leaked?

No. The file contains no passwords, hashes, usernames or payment data. It holds email addresses for every record and, for a minority, names, postal addresses, gender, birthday and phone number.

Is this the same as the WIRED data breach?

It is the rest of it. The WIRED leak of December 2025 covered 2.37 million WIRED accounts. This listing offers the full Condé Nast set of 32.8 million, of which the seller says 2.36 million are WIRED, and the remaining 30.5 million have not appeared publicly before.

Which Condé Nast magazines are affected?

The listing names Vogue, The New Yorker, GQ, Glamour and WIRED, and the December actor also named Vanity Fair. The sample’s demographics point to a database spanning the group’s consumer titles rather than any one magazine. Ars Technica, which Condé Nast owns, runs a separate system and said it was unaffected.

When was Condé Nast hacked?

Account creation dates in the sample run to 23 October 2025 and thin out from September, which points to an extraction between September and late October 2025. The actor contacted DataBreaches.net on 22 November and leaked the WIRED subset on 20 December 2025.

Has Condé Nast confirmed the breach?

Not publicly. No statement has been issued since the December 2025 WIRED leak. Ransomnews has asked the company for comment on the new listing and will update this article with any response.

What should I do if I subscribe to a Condé Nast magazine?

Treat unexpected emails or letters about renewals, billing or gifts with suspicion and go to the publisher’s site directly. No password reset is needed on this evidence, and checking whether your email address has appeared in stealer logs is a more useful step than worrying about this file alone.

Sources and further reading

  • Ransomnews Research Team analysis of the seller’s 5,000-row sample, 7 September 2026 (aggregate statistics only)
  • BleepingComputer: hacker claims to leak WIRED database with 2.3 million records
  • DataBreaches.net: Condé Nast gets hacked, and DataBreaches gets “played”
  • SecurityWeek: hacker claims theft of 40 million Condé Nast records after WIRED data leak
  • Ars Technica: Condé Nast user database reportedly breached, Ars unaffected
  • 7.3M chess.com records leaked, and the data is real, the same verification method applied to a scraped dataset
  • StealerCheck: check whether an address appears in stealer logs

This analysis is part of the Ransomnews breach verification desk, where every verdict and the tests behind it are collected.

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleConfirmed ransomware attacks, August 2026: 51 verified so far, Qilin leads
Next Article Medusa ransomware: victims, tactics, and how to defend in 2026
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

The Town 2025 ticketing data sold as a Ticketmaster breach

September 3, 2026

Micro-Comm hack is separate from the US water attacks

September 1, 2026

Love Electric driver data for sale: NI, licence numbers

August 28, 2026

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,520 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.