Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED Leak
Condé Nast Data Breach (TL-2026-2383), also tracked as Condé Nast Identity Platform Breach 2025, is a high-severity data breach, first published 2026-09-07. It is attributed to Lovely with medium confidence, affects Condé Nast Centralized Identity Platform, maps to 13 MITRE ATT&CK techniques (T1048, T1059, T1087), and is covered by 9 detection rules and 6 indicators of compromise.
Key facts for TL-2026-2383
- Threat ID
- TL-2026-2383
- Also known as
- Condé Nast Identity Platform Breach 2025, WIRED Database Leak
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-09-07
- Last reviewed
- 2026-09-07
- Attribution
- Lovely
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- news - media, publishing, digital-media, consumer-services
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 6
A database of 32,815,767 Condé Nast user records spanning Vogue, The New Yorker, GQ, Glamour, WIRED, Vanity Fair, and other publications has been listed for $15,000 on a Russian-language cybercrime forum. The dataset, described as the full collection behind the December 2025 WIRED leak, was verified by Ransomnews via a 5,000-record sample. Approximately 30.5 million records are not previously public. All records contain email addresses, 31.6% include full names, and 22.3% include postal addresses — no passwords, hashes, or payment-card data are present. Condé Nast has not publicly confirmed the breach.
How Condé Nast Data Breach works
On 7 September 2026, a listing appeared on a Russian-language cybercrime forum offering 32,815,767 Condé Nast user records for $15,000. The seller, a newly-registered account with little reputation offering escrow, claims the dataset is the full database behind the December 2025 WIRED leak. Ransomnews analyzed a 5,000-record sample and confirmed the data as genuine Condé Nast account information captured between September and late October 2025 through a series of IDOR and broken access control vulnerabilities.
The breach originated in Condé Nast's centralized identity platform — a shared account system used across all major publications including WIRED, Vogue, The New Yorker, GQ, Vanity Fair, Glamour, Allure, Architectural Digest, Bon Appétit, Condé Nast Traveler, SELF, Epicurious, Teen Vogue, Golf Digest, and Men's Journal. The platform's subscriber profiles were indexed by predictable, sequential user IDs, enabling an attacker to systematically iterate through these IDs and query backend APIs to retrieve profile data at scale. The backend APIs failed to consistently enforce authorization checks, and compoundingly, account management endpoints lacked sufficient authentication, reportedly allowing unauthenticated users to modify profile attributes such as email addresses and passwords. No API rate limiting or request throttling was in place to detect or block the bulk enumeration.
The attacker, using the alias 'Lovely,' initially contacted Dissent Doe of DataBreaches.net on 22 November 2025, posing as a security researcher seeking help with responsible disclosure. Lovely claimed to have found six vulnerabilities and reported they had only downloaded a small number of records as proof. After Condé Nast reportedly failed to respond for weeks, Lovely later admitted to having downloaded the entire database of over 33 million accounts. On 20 December 2025, Lovely leaked the WIRED subset of 2,366,576 records on the Breach Stars hacking forum, offering access for approximately $2.30 in forum credits and threatening to release 40+ million additional records.
The dataset for sale on the Russian-language forum contains 32,815,767 records, all with email addresses. First and last names appear in 31.6% of records, postal addresses in 22.3%, gender in 17.5%, date of birth in 12.6%, and phone numbers in 2.9%. A version of the dataset excluding WIRED contains 30,455,594 records — approximately 30.5 million records that have not surfaced publicly before. The sample's field completion rates matched the seller's claims within 1.2 percentage points. Validation checks showed 96.4% of U.S. ZIP codes matched the listed state, 93.5% matched the listed city, and 61.9% of full names had matching email addresses (versus 0.3% when shuffled). Account-creation dates in the sample range from February 1999 to 23 October 2025, with new accounts thinning sharply after September 2025 — consistent with extraction over several weeks during that period.
The data was independently verified by multiple parties. BleepingComputer validated 20 records as legitimate WIRED subscribers. Hudson Rock (co-founder Alon Gal) confirmed the authenticity of the WIRED leak by cross-referencing subscriber credentials against RedLine and Raccoon infostealer malware logs. The WIRED dataset was added to Have I Been Pwned on 27 December 2025. Troy Hunt noted that 81% of the records were already in HIBP from prior breaches.
While no passwords, password hashes, or payment-card data are present in the dataset, the exposed PII presents significant risks. A buyer could deploy targeted phishing campaigns referencing real subscriptions, names, and addresses to achieve high credibility. Physical mail scams referencing magazine titles are a risk given the 22.3% of records with postal addresses. The data can also be correlated with other breach datasets for identity fraud, used for credential-stuffing preparation, and leveraged for social engineering attacks. The absence of a public breach notification from Condé Nast raises potential regulatory exposure under GDPR (72-hour notification requirement), CCPA (California resident notification), and New York state breach notification laws. Condé Nast is privately held, so SEC disclosure rules do not apply; no regulatory fines or enforcement actions have been announced as of this writing.
MITRE ATT&CK techniques used in TL-2026-2383
Exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1106 Native API
Discovery
T1087 Account Discovery; T1580 Cloud Infrastructure Discovery
Collection
T1119 Automated Collection; T1213 Data from Information Repositories
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application
Impact
Reconnaissance
T1589 Gather Victim Identity Information; T1595 Active Scanning
Affected products and versions in Condé Nast Data Breach
- Condé Nast — Centralized Identity Platform
Vulnerable versions: Pre-patch (Nov 2025)
Fixed in: Post-remediation (Dec 2025) - Condé Nast — WIRED.com
Vulnerable versions: All versions before Dec 2025 - Condé Nast — Vogue.com / Vogue Digital Edition
Vulnerable versions: All versions before Dec 2025 - Condé Nast — The New Yorker Website
Vulnerable versions: All versions before Dec 2025 - Condé Nast — GQ.com / GQ Digital Edition
Vulnerable versions: All versions before Dec 2025 - Condé Nast — Vanity Fair Website
Vulnerable versions: All versions before Dec 2025 - Condé Nast — Glamour.com / Glamour Digital Edition
Vulnerable versions: All versions before Dec 2025 - Condé Nast — Architectural Digest Website
Vulnerable versions: All versions before Dec 2025 - Condé Nast — Bon Appétit Website
Vulnerable versions: All versions before Dec 2025 - Condé Nast — Condé Nast Traveler Website
Vulnerable versions: All versions before Dec 2025
Remediation for Condé Nast Data Breach
Immediate actions
- Issue public breach notification to affected users across all Condé Nast brands
- Offer credit monitoring and identity theft protection services to affected users
- Implement mandatory MFA for all account management actions (email/password changes)
- Deploy rate limiting and request throttling on all identity platform API endpoints
- Audit and remediate object-level authorization on all account/profile APIs
Workarounds
- Users should monitor for targeted phishing emails referencing real subscription details
- Be cautious of physical mail referencing magazine subscriptions or renewal offers
- Enable 2FA on all Condé Nast accounts where available
- Use unique passwords across all services (password manager recommended)
- Check Have I Been Pwned for exposure of associated email addresses
Longer-term hardening
- Replace sequential user IDs with non-guessable identifiers (UUIDs or hash-based IDs)
- Implement comprehensive object-level authorization checks on every API endpoint
- Deploy WAF rules and API gateway protections to detect and block bulk enumeration patterns
- Segment the shared identity platform to limit blast radius across individual brands
- Adopt zero-trust architecture principles for identity and access management
- Implement comprehensive API security monitoring with anomaly detection for abnormal access patterns
- Establish a responsible disclosure program with clear response SLAs to prevent researcher frustration
Weaknesses (CWE) in Condé Nast Data Breach
CWE-639, CWE-862, CWE-770
Timeline of Condé Nast Data Breach
- Earliest account creation timestamp in the WIRED dataset (April 26, 1996)
- Earliest account creation date in the full 32.8M-record dataset sample
- Data extraction period begins — attacker begins systematic enumeration of Condé Nast's centralized identity platform via IDOR and sequential user ID iteration
- Most recent activity timestamp in the leaked subscriber data
- Latest account creation date in the sample; new accounts drop sharply after September, indicating the extraction window closed
- Actor 'Lovely' contacts Dissent Doe of DataBreaches.net via Signal, posing as a security researcher seeking help with responsible disclosure of six vulnerabilities in Condé Nast's identity platform
- Lovely reportedly reports six vulnerabilities to Condé Nast's security team through a WIRED contact, claiming only a small number of records were downloaded as proof
- Dissent Doe posts publicly on LinkedIn seeking a connection at Condé Nast after the company fails to respond to vulnerability reports
- Lovely leaks the WIRED subset of 2,366,576 subscriber records on the Breach Stars hacking forum, offering access for approximately $2.30 in forum credits; threatens to release 40+ million additional records for other Condé Nast brands
- DataBreaches.net publishes 'Condé Nast gets hacked, and DataBreaches gets played' — Dissent Doe reveals Lovely misled them, having downloaded the entire database while claiming to be a researcher. Concludes: 'As for Lovely, they played me.'
- WIRED dataset added to Have I Been Pwned (Troy Hunt). Hudson Rock publishes independent verification of the data's authenticity via infostealer log cross-referencing (RedLine and Raccoon malware). 81% of records already in HIBP from prior breaches.
- BleepingComputer independently validates 20 records as legitimate WIRED subscribers. SecurityWeek and eSecurity Planet publish technical analyses attributing the breach to IDOR, broken access control, and missing rate limiting.
- Full database of 32,815,767 Condé Nast user records listed for $15,000 on a Russian-language cybercrime forum. The seller (new account, little reputation, offering escrow) claims it is the full dataset behind the December WIRED leak. Ransomnews verifies a 5,000-record sample as genuine, noting ~30.5 million records not previously public.
Sources cited for Condé Nast Data Breach
- Security Affairs — Condé Nast data of 32.8 million users offered for sale after WIRED leak
- Ransomnews — Condé Nast database sale report (original verified sample analysis)
- BleepingComputer — Hacker claims to leak WIRED database with 2.3 million records
- SecurityWeek — Hacker Claims Theft of 40 Million Condé Nast Records After Wired Data Leak
- DataBreaches.net — Condé Nast gets hacked, and DataBreaches gets 'played'
- Hudson Rock — WIRED Database Leaked: 40 Million Record Threat Looms for Condé Nast
- Have I Been Pwned — WIRED Data Breach
- eSecurity Planet — 2.3M WIRED Subscriber Records Leaked in Condé Nast Data Breach (IDOR Technical Analysis)
- Cyber Security News — WIRED Database Breach: 2.3 Million Records Exposed
- SiliconANGLE — Millions of Wired user records leaked in claimed Condé Nast breach
- HackRead — Hacker Behind Wired.com Leak Now Selling Full 40M Condé Nast Records
- Infostealers.com — WIRED Database Leaked: 40 Million Record Threat Looms for Condé Nast
- The Cyber Trove — WIRED Subscriber Data Breach: Condé Nast 2.3 Million Records
- Dissent Doe (LinkedIn) — Does anyone have a connection at Condé Nast?
- Troy Hunt (LinkedIn) — Have I Been Pwned: WIRED Data Breach
More in data breach
- Coordinated GitHub API Enumeration and Access Token Abuse Campaign
- DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patients
- PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)
- ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and Salesforce/Snowflake Compromise
- Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations System
Detection coverage for TL-2026-2383
As of 2026-09-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2383 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.