A “spectacular” ad on a cybercrime forum claims to be selling a database of 340 million records related to OnlyFans (creators and subscribers). However, according to Hackread, the dataset does not appear to come from a direct breach of the platform: the seller reportedly admitted that the material was compiled from previous leaks and publicly available information, “matching” data to OnlyFans accounts.

Why this matters even if it is NOT a “new breach”
The data market has changed: attackers don't always need a new hack. If they can associate email/phone/username with online identities and social profiles, they build "identity graphs" that are extremely useful for:
– spear phishing,
– extortion/blackmail,
– targeted harassment and doxxing,
– impersonation,
– credential stuffing (if combined with passwords from other leaks).
See also: OnlyFans as bait for distributing CRPx0 malware
What the OnlyFans dataset is supposed to contain
The ad describes fields such as usernames, names, emails, phones, metrics (followers/likes), linked social profiles, and even a “card” field that supposedly has the last 4 digits of a card. Hackread says it was unable to confirm whether this “card” is authentic or just a “bait” to increase the value of the alleged leak.
Tests performed on samples
The report states that samples contained usernames and details that matched real/publicly accessible accounts (so at least some of the mapping is real). This does not prove an OnlyFans breach, but it does indicate that the dataset can be used operationally by fraudsters.
See also: The most common phishing scams in Gmail and Outlook

The most likely scenario: Correlation with old leaks
The seller reportedly said that he did not breach OnlyFans and that he used older leaked databases (e.g. from other social media) and public data to create the list. The result is a “ready-made” list of targets.
Practical protection tips (for users)
1) If you use the same email/phone everywhere, consider separating them (separate email for subscriptions/services).
2) Enable MFA where available, but prefer app-based (not SMS).
3) Watch out for phishing that pretends to be OnlyFans or “verification” emails.
4) Do not open links from DMs/suspicious emails and do not provide payment details to pages that are not the official domain.
5) If you are a creator, consider operational security: separate social accounts/phones, limiting public details that help “matching”.
See also: Laravel-Lang: Supply chain attack with credential stealing malware
What does it mean for Greece / businesses / users
– For Greek users/creators, the main risk is not only fraud, but also targeted exposure (doxxing) or extortion, especially if the online profile with a real identity.
– For businesses/brands: such “association lists” fuel BEC-style attacks and social engineering, because they provide more convincing target profiles.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
