A hacker claims to have breached Condé Nast and leaked an alleged WIRED database containing more than 2.3 million subscriber records, while warning that he plans to release up to 40 million additional records for other Condé Nast properties.
See also: The rise of North Korean hackers: $2 billion in cryptocurrencies stolen

On December 20, a malicious actor named “Lovely” leaked the database on a hacking forum, offering access to the site’s credit system for about $2.30 . In the post, Lovely accused Condé Nast of ignoring vulnerability reports and claimed that the company doesn’t take security seriously.
“Condé Nast doesn’t care about the security of its users’ data. It took us a whole month to convince them to fix vulnerabilities on their websites,” reads a post on a hacking forum.
“We will be leaking more of their user data (40+ million) in the coming weeks. Enjoy!“
The same person later leaked the data to other hacking forums, where users also had to spend forum credits to reveal the password to the file containing the data.
Lovely also shared subscription numbers for other Condé Nast properties that he claims stole data from, including The New Yorker, Epicurious, SELF, Vogue, Allure, Vanity Fair, Glamour, Men's Journal, Architectural Digest, Golf Digest, Teen Vogue, Style.com, and Condé Nast Traveler.
See also: APT28 targets UKR.net users in Ukraine in long-running phishing campaign

While Condé Nast has yet to confirm that it was breached, BleepingComputer analyzed the leaked database and was able to validate twenty of the records as legitimate WIRED subscribers. The dataset contains a total of 2,366,576 records and 2,366,574 unique email addresses, with timestamps ranging from April 26, 1996 to September 9, 2025.
Each record includes a unique internal subscriber ID, an email address, and optional data such as first and last name, phone number, physical address, gender, and date of birth. Many of these fields are blank. Records also include account creation and update timestamps, last session information, and WIRED-specific fields such as display username and WIRED account creation and update dates.
While many of the record fields are blank, some include additional personal details. A much smaller subset includes more complete profiles, with 1,529 records (0.06%) containing full name, date of birth, phone number, address, and gender.
Alon Gal, co-founder and CTO of Hudson Rock, also verified the records using infostealer logs containing previously compromised credentials.
See also: Hackers impersonated law enforcement to steal Apple account data

The database leak has been added to Have I Been Pwned, allowing users to check if their email addresses were exposed by the data leak.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
