Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak
Condé Nast Data Breach 🚨
Condé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud, and scams. A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a 5,000-record sample and concluded that it is consistent with genuine Condé Nast account data collected between September and late October 2025, including records that have not appeared publicly before.
The alleged dataset covers users across Condé Nast’s publishing portfolio, which includes Vogue, The New Yorker, GQ, Glamour, WIRED, Vanity Fair, and other titles. Condé Nast has not publicly confirmed the breach or commented on the new sale listing. The seller claims the database contains 32,815,767 unique email addresses. It also allegedly includes names, postal addresses, gender, dates of birth, and phone numbers for portions of the population, but no passwords, password hashes, usernames, or payment-card data.
Key Findings 🔍
- A database of 32,815,767 Condé Nast user records went on sale on a Russian-language hacker forum on September 7, 2026, for $15,000, offered as the full set behind December’s WIRED leak.
- Ransomnews tested the 5,000-row sample: it is genuine Condé Nast account data, captured in September and October 2025, and the 30.5 million non-WIRED records have not surfaced publicly before.
- The listing claims to include the full dataset behind the December 2025 leak involving WIRED.
Risks of Data Exposure ⚠️
A private sale can produce a more focused problem: a buyer can use the data for phishing, lead generation, fraud, credential-stuffing preparation, or correlation with other leaked datasets without ever publishing the full file. The absence of passwords does not make the data harmless. A person who subscribed to Vogue, booked a gift subscription for GQ, or registered for The New Yorker may receive a message that accurately uses their name, address, and publication relationship. That is enough to make a fake renewal, refund, or billing request look far more credible than ordinary spam.
Readers should treat unexpected messages about subscription renewals, billing problems, delivery issues, gifts, or account verification with caution. Instead of using an email link, open the publisher’s website directly through a known address and check the account there. Anyone who reused the same email address across many services should be alert to follow-on phishing and should use a password manager and multi-factor authentication on important accounts.
Conclusion 📌
Postal addresses were present in more than one-fifth of the claimed records. That means fraud may also arrive as physical mail.