A database of 32,815,767 Condé Nast user records went on sale on a Russian-language hacker forum on 7 September 2026 for $15,000, offered as the full set behind December’s WIRED leak. Ransomnews tested the 5,000-row sample: it is genuine Condé Nast account data, captured in September and October 2025, and the 30.5 million non-WIRED records have not surfaced publicly before. Condé Nast has never commented on the breach.
A note on what we are publishing. The sample is the personal data of real people. We reproduce none of it. Every figure below is an aggregate: counts, match rates, date ranges and distributions, never a record. We do not link the sample or name the forum, we have removed the seller’s details and the download links from the screenshot, and we did not test any address against a live Condé Nast account.

What is being sold
The listing is titled “[33M users – USA] Condé Nast Database [UNTOUCHED, PRIVATE]” and was posted by an account which, according to its profile, registered on 5 September 2026 with a paid membership and has one post and no reputation. In line with our policy, we are not publishing the handle. It offers 32,815,767 records, each with a unique email address, and gives field counts for the rest: 10,367,773 records with a first and last name, 7,317,721 with a postal address, 5,750,346 with a gender, 4,135,784 with a birthday and 966,388 with a phone number. The price is a $15,000 “blitz”, with escrow offered.
Two lines in the post matter more than the numbers. The seller writes that the database “comes with the same database but with WIRED.com records removed because we leaked the WIRED.com database before (subset of this database)”, and that the version without WIRED has 30,455,594 lines. That is a direct claim to be the actor behind the December 2025 WIRED leak, and it is checkable arithmetic: 32,815,767 minus 30,455,594 leaves 2,360,173 WIRED records. The WIRED file published on 20 December 2025 held 2,366,576 records, according to BleepingComputer. The two figures differ by 0.27%.
The sample is a 5,000-row CSV with fourteen columns: an account ID, a creation date, email, phone, gender, first name, last name, birthday, two address lines, city, zip code, state and country. There are no passwords, no password hashes, no usernames and no payment data anywhere in the schema.
How we verified the sample
Nothing in this file can be checked against a live system without touching other people’s accounts, so every test is internal: does the data behave like a real consumer database, and does it behave like Condé Nast’s? Four tests carry most of the weight.
First, the seller’s own statistics. If the sample is a random draw from the file the seller counted, its field fill rates should match the shares in the listing. They do: 31.7% of sample rows carry a first name against 31.6% claimed, 22.2% carry a street address against 22.3%, 12.1% a birthday against 12.6%, 16.4% a gender against 17.5%, 3.5% a phone number against 2.9%. The rows are in no sort order. That is a random sample of the file the seller described, not a curated showcase.
Second, the names belong to the email addresses. Among the 1,558 rows with a full name, 61.9% have that name, or an initial-plus-surname form of it, inside the email address. When we shuffled the names between rows and ran the same test, the match rate fell to 0.3%. Generated data does not produce that correlation; only records where the same person typed both fields do.
Third, time. Every email provider has a launch date, and an account cannot have been registered with an address that did not exist yet. The sample has 88 Apple private-relay addresses, 67 iCloud, 30 outlook.com, 39 me.com and 3 Proton addresses. None of the 227 was created before its provider launched. The earliest Apple relay account dates from October 2020; the service began in September 2019.
Fourth, geography. Of the 1,230 US rows that carry both a zip code and a state, 96.4% agree, and 93.5% of zip codes agree with the stated city. The mismatches are the useful part. One state field holds the literal text “Select your state”, another holds “37”, the index of a dropdown option rather than its label, others read “California”, “mi.” or “NEWYORK”. Those are the fingerprints of web forms filled in by people over two decades. Nobody fabricating a database puts them in.
| Check | Result | What it means |
|---|---|---|
| Fill rates vs seller’s totals | Within 1.2 points on all five fields | Random sample of the described file |
| Name found in email address | 61.9%, vs 0.3% shuffled | Names and emails belong together |
| Provider launch dates | 0 violations in 227 accounts | Creation dates are real |
| Zip code vs state (US) | 96.4% match, 1,186 of 1,230 | Addresses are real; errors are human |
| Account creation dates | 9 February 1999 to 23 October 2025 | Dates the capture |
| Stated gender | 77% female (633 F, 186 M) | Fits Vogue, Glamour and Allure, not WIRED |
| Passwords or payment data | None | No credential exposure in this file |

The rest of the file is messy in the way a 26-year-old consumer database is messy. A fifth of the birthdays fall on 1 January, the signature of a form that asked for a year. Three people are recorded with ages over 100. Twenty-two email addresses are test or placeholder accounts. 283 first names are entirely lower case. The country field uses both “UK” and “GB”. Gmail accounts for 45% of addresses, Yahoo 13%, Hotmail 8%, AOL 4%, with a long tail of 772 domains that includes legacy regional US cable and telephone providers. Where a country is stated, 82% of rows say United States, which matches the listing’s “USA” label and Condé Nast’s home market.
Is this the same data as the WIRED leak?
It is the same breach and a different, much larger slice of it. The WIRED file was leaked on 20 December 2025 by an actor using the handle Lovely, who had contacted DataBreaches.net a month earlier posing as a researcher. Lovely claimed six vulnerabilities in Condé Nast’s account system that allowed any account’s details to be viewed and its email and password changed, and said they had “downloaded all 33 million user’s information”, as DataBreaches.net reported. On the forums, the actor threatened to release “40+ million” further records from The New Yorker, Vogue, Vanity Fair, Glamour and other titles over the following weeks. SecurityWeek’s reading of the technical claims was insecure direct object reference and broken access control flaws.
Three things tie the new listing to that episode. The row count, 32.8 million, is the “33 million” Lovely described. The implied WIRED subset matches the leaked WIRED file to within 0.27%. And the sample is not simply the public WIRED dump resold under a new label: the WIRED file had names on 12% of records and addresses on 8%, this sample has 32% and 22%; the WIRED file carried display usernames, this schema has none; and the stated gender in this sample runs 77% female, the opposite of WIRED’s readership and exactly what a database dominated by Vogue, Glamour, Allure and Bon Appétit registrations should look like.
// Free tool
How does your own site score?
Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.
No signup. Nothing installed. We only request what your site already serves publicly.
What we cannot prove is that the seller is Lovely. The handle, the claim and the numbers are consistent with it; a buyer or an associate holding the same file would look identical from the outside. The listing’s “never sold before” is the seller’s word.
When the data was taken
The creation dates put a clock on the intrusion. Accounts in the sample were registered between 9 February 1999 and 23 October 2025. Through the first eight months of 2025 the sample holds 20 to 36 new accounts per month; September has 8 and the first 23 days of October have 4. Condé Nast did not stop acquiring readers in September 2025, so the shortfall is the extraction itself: a harvest that ran for weeks, picking up new accounts only partially as it went, and stopped in the last days of October. That window sits after the WIRED file’s own last record on 9 September 2025, and before Lovely’s first message to DataBreaches.net on 22 November. Whoever pulled this file had access to Condé Nast’s account system across September and October 2025 and, by the actor’s own account, it then took a further month to persuade the company to fix the flaws.
Who is selling it
The forum is one of the established Russian-language cybercrime markets, fee-gated and closed to casual visitors, and a listing there reaches a smaller and more professional audience than the English-language leak sites where the WIRED file was given away for forum credits. The seller’s account is two days old, paid for its membership, has a single post and no reputation, and is offering escrow, which on that forum means the buyer’s money is held by the administration until the goods are checked. That is the profile of someone who wants one quiet sale to a buyer with a use for 32 million profiled email addresses, not attention.
The price tells the same story. Fifteen thousand dollars for 32.8 million records is under a twentieth of a cent per record. The value is not in any one row; it is in a fifth of them carrying a name, a street address and a zip code, a filterable gender field, and subscription histories to some of the most affluent readerships in American publishing.
What Condé Nast readers should do
Start with what is not in the file. There are no passwords or hashes, so this data alone cannot be used to log into an account, and a password reset is not the urgent step it would be after a credential breach. The risk is targeted mail.
- Expect subscription phishing. An email address next to a real name, a home address and the magazine it belongs to is enough to write a convincing renewal notice, a billing problem or a gift offer from Vogue, The New Yorker or GQ. Reach the publisher’s site directly rather than through a link.
- Treat physical mail with the same suspicion. A fifth of the records carry a full postal address. Fraudulent “your subscription has lapsed” letters are cheaper than ever to target.
- Check the address, not the account. If the email in this file is one you reuse elsewhere, the reuse is the exposure. Our StealerCheck tool shows whether an address has surfaced in stealer logs, a materially worse category of exposure than a marketing profile.
- If you had a WIRED account, this changes little. Those records were already public in December. The new exposure is for readers of every other Condé Nast title.
What this means
Nine months after its account system was copied, Condé Nast has issued no public statement. It did not answer SecurityWeek’s questions in December, and the only public word from inside the group came from Ars Technica, which Condé Nast owns and which said its own separate stack was unaffected. We found nothing since. WIRED’s 2.3 million records were added to Have I Been Pwned. The other 30.5 million people in this file have had no equivalent, because the file was never dumped. It was held, and now it is priced.
That is the pattern to expect more of. An actor who leaks a small brand-name slice for free establishes that the haul is real, then sells the bulk quietly where the buyers are. The public sees the leak; the market sees the sale. For the reader whose Glamour subscription from 2014 is in this file, the difference is academic.
We approached this listing the way we approach every one on Ransomtracker: assume the seller is exaggerating, then test what they handed over. The sample held up on every test we could run without touching a live account. We have contacted Condé Nast for comment, including whether the flaws Lovely described were closed and whether affected readers outside WIRED were ever notified, and will update this article with any response. Press contact for this piece is [email protected].
Frequently asked questions
Is the Condé Nast database for sale real?
The sample is. Ransomnews tested the seller’s 5,000-row sample and it behaves like genuine Condé Nast account data on every internal test: fill rates match the seller’s totals, names match email addresses, no account predates its email provider, and 96% of US zip codes agree with the stated state. The full 32.8 million-row count is the seller’s claim.
Were Condé Nast passwords leaked?
No. The file contains no passwords, hashes, usernames or payment data. It holds email addresses for every record and, for a minority, names, postal addresses, gender, birthday and phone number.
Is this the same as the WIRED data breach?
It is the rest of it. The WIRED leak of December 2025 covered 2.37 million WIRED accounts. This listing offers the full Condé Nast set of 32.8 million, of which the seller says 2.36 million are WIRED, and the remaining 30.5 million have not appeared publicly before.
Which Condé Nast magazines are affected?
The listing names Vogue, The New Yorker, GQ, Glamour and WIRED, and the December actor also named Vanity Fair. The sample’s demographics point to a database spanning the group’s consumer titles rather than any one magazine. Ars Technica, which Condé Nast owns, runs a separate system and said it was unaffected.
When was Condé Nast hacked?
Account creation dates in the sample run to 23 October 2025 and thin out from September, which points to an extraction between September and late October 2025. The actor contacted DataBreaches.net on 22 November and leaked the WIRED subset on 20 December 2025.
Has Condé Nast confirmed the breach?
Not publicly. No statement has been issued since the December 2025 WIRED leak. Ransomnews has asked the company for comment on the new listing and will update this article with any response.
What should I do if I subscribe to a Condé Nast magazine?
Treat unexpected emails or letters about renewals, billing or gifts with suspicion and go to the publisher’s site directly. No password reset is needed on this evidence, and checking whether your email address has appeared in stealer logs is a more useful step than worrying about this file alone.
Sources and further reading
- Ransomnews Research Team analysis of the seller’s 5,000-row sample, 7 September 2026 (aggregate statistics only)
- BleepingComputer: hacker claims to leak WIRED database with 2.3 million records
- DataBreaches.net: Condé Nast gets hacked, and DataBreaches gets “played”
- SecurityWeek: hacker claims theft of 40 million Condé Nast records after WIRED data leak
- Ars Technica: Condé Nast user database reportedly breached, Ars unaffected
- 7.3M chess.com records leaked, and the data is real, the same verification method applied to a scraped dataset
- StealerCheck: check whether an address appears in stealer logs
This analysis is part of the Ransomnews breach verification desk, where every verdict and the tests behind it are collected.
The Ransomnews Monthly
One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.
Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.
