32.8 Million Alleged Condé Nast Records Offered for $15,000

A seller is offering 32.8 million alleged Condé Nast user records for $15,000, potentially exposing subscriber details useful for targeted phishing.

Sep 10, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

If you subscribe to Vogue, The New Yorker, or GQ, details about more than your reading habits may be circulating on a cybercrime forum.

A database claiming to contain 32,815,767 user records tied to publishing titan Condé Nast surfaced on a Russian-language cybercrime forum on Sept. 7, 2026, with an asking price of $15,000. 

Cybersecurity outlet Ransomnews examined a 5,000-row sample of the dataset and verified that it reflects authentic user details gathered between September and late October 2025. While a 2.3-million-record subset involving WIRED was dumped publicly in December 2025, the remaining 30.5 million records have not previously circulated. 

Condé Nast has not publicly commented on the dataset or the seller’s claims.

Inside the leak

The anonymous seller offers the complete bundle or a trimmed 30,455,594-record version with the earlier WIRED accounts removed. That math closely aligns with the 2,366,576 WIRED records released on Dec. 20, 2025, by a threat actor going by “Lovely.” SecurityWeek previously noted that Lovely claimed to exploit broken access control and insecure direct object reference (IDOR) flaws within Condé Nast’s account system.

Ransomnews verified the sample through internal consistency checks:

  • Fill rates matched the listing’s profile within 1.2 percentage points.
  • 61.9% of full names naturally matched the accompanying email handle, compared to just 0.3% when randomized.
  • None of the 227 email addresses using newer providers like Apple Relay predated those platforms’ launches.
  • 96.4% of U.S. ZIP codes correctly matched their designated state.

Every row contains a unique email address. Additionally, roughly 31.6% include first and last names, 22.3% contain physical street addresses, 17.5% list gender, 12.6% state a birth date, and 2.9% list a telephone number. The dataset contains no passwords, password hashes, usernames, or payment card details.

Advertisement

The publisher data dilemma

Editorial conglomerates operate under an architectural model where reader databases function as advertising engines, compiling identity breadcrumbs across dozens of disparate magazine properties into centralized profiles. 

When compromised, these repositories create an asymmetrical threat. Because credentials were not exposed, automated security tools will not flag immediate credential-stuffing attacks.

Instead, attackers gain a weaponized consumer directory. By tying real names and physical home addresses to specific cultural interests, bad actors can construct sophisticated, hyper-targeted spear-phishing and mail-fraud schemes

An email claiming a subscription billing glitch with The New Yorker or a physical postcard advertising a Vogue renewal discount appears far more convincing than generic spam.

Consumer defense steps

While a password reset on Condé Nast sites is not immediately required based on this file’s schema, readers should take defensive precautions:

  • Treat unexpected renewal notices, delivery updates, or subscription billing alerts with skepticism.
  • Go directly to the publisher’s official website in your browser rather than clicking links in unsolicited communications.
  • Inspect physical mail claiming to represent magazine subscriptions, as postal addresses are present in over 7.3 million alleged records.
  • Maintain unique passwords and multi-factor authentication across your core personal email accounts to guard against secondary phishing efforts.

Because the alleged dataset does not contain passwords, changing a Condé Nast password solely in response to this listing may not address the primary risk. Readers should instead be particularly cautious of messages that appear unusually well informed about their subscriptions or personal details.

Advertisement

The danger with data like this is context. A scammer does not necessarily need a password if knowing your name, address, and preferred magazine is enough to make the next phishing message look legitimate.

More security news: Hackers are abusing trusted Google services to disguise phishing links that steal Microsoft credentials and, in some cases, install ScreenConnect for persistent remote access.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.