Cyber & AI intelligence
Wasteland.
Briefs indexed2466
Issues27
Published Mondays07:30 CT
▣ Breach CONDE-NAST-WIRED 2026-09-07

Condé Nast: 32.8 Million Account Records Listed for Sale After WIRED Leak

"A database advertised as containing 32,815,767 Condé Nast user records went up for sale on a Russian-language cybercrime forum on 7 September 2026 for $15,000, offered by the seller as the full dataset behind the WIRED…"

A database advertised as containing 32,815,767 Condé Nast user records went up for sale on a Russian-language cybercrime forum on 7 September 2026 for $15,000, offered by the seller as the full dataset behind the WIRED subscriber leak that surfaced in December 2025. Security Affairs, citing analysis by Ransomnews, reports that a 5,000-row sample was reviewed and assessed as genuine Condé Nast account data captured between September and late October 2025, with roughly 30.5 million of the records never having appeared publicly before. Condé Nast has not confirmed the breach, has not commented on the sale listing, and did not respond to press inquiries at the time of the original December leak. Every source in this brief is press or independent research; there is no victim statement, regulator filing, or CERT advisory to weigh against them, and readers should treat the entire incident as attacker-claimed and third-party-verified rather than company-confirmed.

What Happened

The incident has two stages roughly nine months apart.

In December 2025, a threat actor using the alias "Lovely" posted on a hacking forum claiming to have breached Condé Nast and dumped a WIRED subscriber database. Reporting places the post on 20 December. Record counts for that first dump differ slightly across accounts: TechBloat describes it as "more than 2.3 million records" and notes a WIRED entry of approximately 2.3 million appearing in Have I Been Pwned, while WebWideStudios and DianaSonis both give the precise figure 2,366,576 records, with DianaSonis adding 2,366,574 unique email addresses and account timestamps spanning from 26 April 1996 onward. That first dataset was not sold at a premium; multiple accounts state it was made available across several forums for the equivalent of about $2.30 in site credits.

In the same December post, Lovely threatened to release a further 40 million or more records drawn from other Condé Nast titles "over the next few weeks." That threat did not materialise on the stated timeline. The 7 September 2026 listing is the first sign of the wider dataset, and at 32.8 million records it is materially smaller than the 40 million-plus the actor originally advertised. Whether that reflects an inflated original boast, a partial dataset, or a deliberately trimmed sale package is not established by any source here.

Attribution of the September listing to Lovely is not directly stated in the reporting. What the seller claims, and what Ransomnews' sample testing supports, is continuity of the underlying data: the September 2026 offering is presented as the parent set from which the December WIRED dump was drawn.

What Was Taken

The September listing covers accounts across Condé Nast's publishing portfolio, including Vogue, The New Yorker, GQ, Glamour, WIRED, Vanity Fair, and Teen Vogue. The core field is email address, present across all 32,815,767 records per the seller's claim.

Ransomnews' analysis of the sample, as relayed by Security Affairs, gives the following completeness rates for supplementary fields:

Notably absent, according to the same analysis: no passwords, no password hashes, no usernames, and no payment card data. That is consistent across the December reporting as well, where TechBloat explicitly states the available evidence does not establish that passwords or card numbers were exposed.

The December WIRED subset was described as carrying additional publication-specific fields beyond the above: internal account IDs, account-creation dates, last-session data, and WIRED subscription metadata.

One figure is worth flagging as an outlier. FavouriteDaughter reports that only around 1,529 records in the leaked data contained complete personal profiles. That is a single lower-tier source and sits awkwardly against the percentage breakdown above, though the two may simply be measuring different things: full-profile completeness across every field versus per-field presence rates, and possibly across different datasets. Treat the 1,529 figure as attributed, not established.

The practical read is that this is a partially-populated marketing and subscription dataset, not a credential dump. Its value to a buyer is in filtering and enrichment: pulling out the subset with names plus postal addresses plus dates of birth, then joining against other breach corpora.

Why It Matters

Verification of the December subset is reasonably firm for a non-confirmed breach. BleepingComputer analysed the database and validated a sample of twenty records as belonging to legitimate WIRED subscribers, and Infostealer is cited alongside it as corroborating. The dataset was ingested into Have I Been Pwned, which gives affected individuals a self-service check. Ransomnews' independent sample testing of the September listing extends that verification to the larger set. Condé Nast's continued silence across roughly nine months means there is no authoritative record count, no confirmed exposure window beyond the September-to-October 2025 capture dates in the sample, and no notification programme visible in any of this reporting.

For defenders, the significance is less about credential risk and more about targeting quality. A 32.8 million-record set that pairs verified email addresses with names, home addresses, and birthdates for a meaningful fraction of the population is high-grade raw material for social engineering, account-recovery attacks against unrelated services, and identity fraud. Condé Nast's readership also skews toward affluent, professional, and media-adjacent demographics, which raises the per-record value for spear-phishing operations well above a generic consumer list.

The pricing arc is its own signal. The WIRED subset went out at effectively $2.30 in forum credits; the full corpus is now listed at $15,000. That is the difference between a reputation-building dump and a commercial sale, and it suggests the actor moved from pressure tactics to monetisation after the victim declined to engage.

There is also an unresolved question of motive that defenders should not gloss over. Lovely framed the leak as a response to ignored vulnerability reports, stating in the forum post that "Condé Nast does not care about the security of their users' data. It took us an entire month to convince them to fix the vulnerabilities on their websites." Independent journalist Dissent Doe of DataBreaches.net, who Lovely initially approached posing as a security researcher seeking responsible disclosure, has publicly characterised the actor as a bad actor pursuing a payout rather than a whistleblower. Sources here do not resolve whether Condé Nast actually received and ignored vulnerability reports; that claim rests entirely on the attacker's own account.

The Attack Technique

The intrusion method is not established. No source in this set describes a confirmed initial access vector, exploited CVE, or intrusion timeline from the victim's side.

What exists is the actor's own framing: Lovely claims to have found and reported vulnerabilities in Condé Nast websites, claims it took a month of pressure before any were addressed, and implies the data was taken via those web-facing weaknesses. That is an unverified attacker assertion, and it comes from a party with an obvious interest in casting the theft as justified disclosure.

The data itself offers one weak forensic hint. The September-to-October 2025 capture window identified in the Ransomnews sample suggests collection over a period of weeks rather than a single smash-and-grab, and the absence of any password or hash material points toward extraction from a marketing, subscription, or CRM-style store rather than a core authentication database. That is inference from data shape, not confirmed finding.

What Organizations Should Do

Sources: Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED... | WIRED Data Leak Claim: What 2.3 Million Records May Include | Massive WIRED Database Leak: What You Need to Know! (2026) | Wired Data Breach: Hacker Threatens to Expose 2.3 Million Subscribe... | Hacker Leaks 2.3 Million WIRED Subscriber Records - Condé Nast Data... | Massive Data Breach: 2.3 Million Wired Subscribers at Risk! (2026) | Massive Data Breach: Hackers Threaten to Leak Wired's Customer Data... | Wired Data Breach: What You Need to Know About the 2.3 Million Reco...