32.8 Million Condé Nast Records Are for Sale. No Passwords Were Taken

Disclosure: Some links on this page are affiliate links. If you purchase through them, we may earn a commission at no extra cost to you. Full affiliate disclosure.

Breach Published September 8, 2026 · 9 min read · By Yongrui Sun
32.8 Million Condé Nast Records Are for Sale. No Passwords Were Taken
32.8 Million Condé Nast Records Are for Sale. No Passwords Were Taken

On September 7, 2026, a database of 32,815,767 Condé Nast user records went up for sale on a Russian-language cybercrime forum at $15,000. That works out to roughly half a ten-thousandth of a dollar per record, which tells you something about how this data is meant to be used: not as a trophy, but as raw material for industrial-scale mail and phone campaigns.

Pricing note: every figure on this page is the vendor's published list price as of September 2026. Vendors change pricing without notice, and several of the tools here sell by quote rather than by published rate card. Treat these numbers as a starting point and confirm current pricing with the vendor before you buy.

Condé Nast publishes Vogue, The New Yorker, GQ, Glamour, WIRED and Vanity Fair. If you have ever registered for one of them, or subscribed in print, there is a reasonable chance your email address is in this file.

Here is the part that most coverage will lead with, and the part I want to argue with: there are no passwords in it. No hashes, no usernames, no payment card numbers. The technically accurate summary is "no credentials were exposed," and if you stop reading there you will conclude this is a minor event. It is not, and the reason has nothing to do with passwords.

Editor’s take: Three things this guide doesn't cover but you should know: (1) document your actual workflow before buying; (2) ask the vendor for a 30-day pilot, not a 14-day trial; (3) set a hard review date — six months is the magic window. Tackle those after you finish the steps above.

Editor's Take

The detail worth sitting with is that no passwords were in this file — and that does not make it harmless. Names, emails and phone numbers are exactly the inputs phishing and account-recovery attacks need, and they never expire. Note also the price: at a few ten-thousandths of a dollar per record, this data is cheap enough that buying it is trivial, which is why it will be resold for years.

How We Know the Sample Is Real

Breach listings are advertised constantly and a large fraction of them are recycled, padded, or invented. Ransomnews did the thing that separates a real verification from a retweet: it took the seller's free 5,000-row sample and ran internal consistency tests on it, deliberately without attempting to log into any live Condé Nast account.

The checks are worth understanding, because they are the same ones you should mentally apply to the next breach headline:

My favourite detail is the messiness. The file contains placeholder text like "Select your state," numeric dropdown values where a country name should be, inconsistent country labels, lower-case names, and a pile of birth dates set to 1 January. Generated data is clean. Data that accumulated through decades of web forms is embarrassing, and this file is embarrassing in exactly the right ways.

One honest limit: 32.8 million is the seller's claimed row count, and no one has verified all of it. The sample is genuine; the total is not independently confirmed.

What Is Actually in the File

Every record contains an email address. Beyond that, coverage drops off sharply:

Read those numbers as a filtering problem rather than a completeness problem. A buyer does not need every field on every row. They need the roughly 12.6% of records that carry a date of birth, cross-referenced against the 22.3% with an address, intersected with data from the next breach. Name plus address plus date of birth is enough to attempt synthetic identity construction and to get past knowledge-based authentication at institutions that still rely on it.

And the email addresses alone have immediate value as credential-stuffing fuel. No password came from Condé Nast, but a list of 32.8 million confirmed active consumer inboxes is exactly the input to an automated campaign against every other site those people use.

The WIRED Connection

This listing is not isolated. In December 2025, an actor using the name "Lovely" published 2,366,576 WIRED subscriber records and claimed to have taken more than 40 million Condé Nast records overall.

The new listing offers a version with WIRED removed containing 30,455,594 records. Subtract that from 32,815,767 and you get about 2.36 million — a near-exact match for the WIRED figure released in December. The arithmetic lines up neatly enough to link the two events, though it does not prove the current seller is the original intruder. They could be a partner, or someone who bought the data secondhand.

Ransomnews also found that the new sample is not simply a re-upload of the public WIRED data. It has a different field structure, higher rates of names and street addresses, and a demographic distribution consistent with Condé Nast's broader consumer titles rather than WIRED specifically. Account creation dates run from February 1999 to 23 October 2025, thinning sharply after September, which points to an extraction window between September and late October 2025.

The Company Has Not Said Anything

Condé Nast has not publicly confirmed the breach, commented on the sale, or issued any statement since the December 2025 WIRED leak. Ransomnews says it contacted the company asking whether the flaws "Lovely" described were ever closed, and whether readers outside WIRED were ever notified. There has been no response.

That silence is harder to sustain than it used to be. Vogue and GQ have large European readerships, and GDPR Article 33 requires notifying a supervisory authority within 72 hours of becoming aware of a breach. In the US, California's CCPA/CPRA and the state breach notification patchwork apply to the personal data fields present here. Whether any of that was triggered depends on facts only the company has, which is precisely the problem.

One clarification worth making, because it keeps getting muddled: Ars Technica is owned by Condé Nast but runs on a separate system, and has said it was unaffected.

What to Actually Do

I want to be precise here, because the standard advice for breaches does not all apply.

The one step that actually reduces exposure: broker removal. A file like this is dangerous because it joins up with what data brokers already sell about you. Automated removal services file the opt-outs and re-check them, which is the part nobody does manually more than once.

Check PrivacyHawk pricing

For the general sequence after any exposure like this, our data breach response guide walks through triage in order, and our phishing identification guide covers the specific tells in subscription-themed lures.

The Honest Read

"No passwords were stolen" is true and nearly useless. The value of this dataset was never in authentication; it was in confirmation. It confirms 32.8 million people subscribe to specific magazines, and for millions of them it confirms a name, an address and a birth date that can be joined to whatever else is already circulating. Nobody needs to break into anything with this file. They need to send a better email.

We covered the harder version of this problem in the IDScan driver's license breach, where 153 million records included documents that cannot be reissued at all. That was a worse breach by any measure. This one is ordinary, and that is the point: ordinary exposure of ordinary fields, sold for the price of a used car, is enough to keep the phishing pipeline running for years.

YS
Founder & Editor

CyberPicks is published by Yongrui Sun. Every comparison is built from vendor documentation, published pricing, published specifications, and published independent-lab results. We do not run hands-on lab tests, and where a figure comes from a vendor or an independent testing lab we say which on the page.

Sources

How we compared

This report is based on public claims about the dataset and on the sample that was published alongside them.

Frequently asked questions

Were Condé Nast passwords leaked?

No. The listing contains no passwords, password hashes, usernames or payment card data. Every record has an email address, and smaller subsets include names, postal addresses, gender, date of birth and phone numbers.

How do we know the data is real?

Ransomnews tested the seller's 5,000-row sample rather than trusting the listing. Field completion rates matched the seller's totals within 1.2 percentage points, 61.9 percent of records with full names had an email matching the name or its initials, no account predated its email provider, and 96.4 percent of US ZIP codes matched the stated state.

Which magazines are affected?

The listing names Vogue, The New Yorker, GQ, Glamour and WIRED, and the actor behind the December 2025 WIRED leak also named Vanity Fair. The sample's demographics point to a database spanning the group's consumer titles rather than any single magazine. Ars Technica, also owned by Condé Nast, runs a separate system and said it was unaffected.

Has Condé Nast confirmed the breach?

Not publicly. The company has issued no statement since the December 2025 WIRED leak. Ransomnews contacted Condé Nast asking whether the flaws described by the actor were closed and whether affected readers outside WIRED were ever notified, and said it would update with any response.

What should I do if I subscribe to a Condé Nast magazine?

You do not need a password reset on this evidence, since no credentials were in the file. The useful steps are treating unexpected renewal, billing or gift emails with suspicion and navigating to the publisher's site directly, and checking whether your email address appears in stealer logs, since infostealer infections are a more likely route to real account takeover.

32.8 Million Condé Nast Records Are for Sale. No Passwords Were Taken — comparison snapshot
32.8 Million Condé Nast Records Are for Sale. No Passwords Were Taken — comparison snapshot