Ethical Hacking News
A shocking revelation has exposed the sensitive user data of Condé Nast, a prominent publishing house, with a staggering 32.8 million user records being offered for sale on a Russian-language cybercrime forum. The data, valued at $15,000, has raised concerns about targeted phishing, fraud, and scams. With no passwords included in the dataset, experts warn that the breach could be used for malicious purposes, highlighting the importance of data protection and security.
Condé Nast's user data, including 32.8 million records, has been compromised and is being offered for sale on a Russian-language cybercrime forum. The dataset is valued at $15,000 and contains names, postal addresses, gender, dates of birth, and phone numbers. Security experts have expressed concerns about targeted phishing, fraud, and scams due to the sale of sensitive user data. Not all records include all fields, making the data valuable for filtering and combination with other information. The breach is consistent with genuine Condé Nast account data collected between September and late October 2025. Even without passwords, the data can still be used for malicious purposes, such as phishing and scams. The breach highlights the importance of data protection and the need for organizations to prioritize the security of their user data.
In a disturbing revelation, Condé Nast, a prominent publishing house, has found its user data compromised, with a staggering 32.8 million user records being offered for sale on a Russian-language cybercrime forum. The data, which includes names, postal addresses, gender, dates of birth, and phone numbers, is valued at $15,000, sparking concerns about targeted phishing, fraud, and scams.
According to a report by Ransomnews, a database containing 32,815,767 unique email addresses was uploaded on the cybercrime forum, with the seller claiming it is the full set of Condé Nast user data behind the December 2025 leak involving WIRED. The dataset is said to contain 30,455,594 records, which is roughly 90% of the total Condé Nast user base.
Security experts and researchers have expressed their concerns about the sale of sensitive user data, citing the potential risks of targeted phishing, fraud, and scams. The fact that passwords, password hashes, usernames, and payment-card data were not included in the dataset has raised concerns about the potential for malicious actors to use the data for malicious purposes.
The dataset was analyzed by Ransomnews, which found that 31.6% of records allegedly include both first and last names, 22.3% include a postal address, 17.5% include gender, 12.6% include a date of birth, and 2.9% include a phone number. The data is valuable because it can be filtered and combined with other information, not because every record contains every field.
Researchers have noted that the dataset is consistent with genuine Condé Nast account data collected between September and late October 2025, including records that have not appeared publicly before. The timing of the breach fits with the earlier WIRED leak, which contained records dated through September 2025.
Security experts have warned that the absence of passwords does not make the data harmless. A person who subscribed to Vogue, booked a gift subscription for GQ or registered for The New Yorker may receive a message that accurately uses their name, address, and publication relationship. This can make a fake renewal, refund, or billing request look far more credible than ordinary spam.
The breach has also raised concerns about breach economics. An attacker can release a small, recognizable subset to demonstrate that the data is real, then hold the larger collection back until a buyer appears. This can create a sense of urgency, with malicious actors potentially exploiting the situation for their own gain.
In light of this revelation, Condé Nast has not publicly commented on the breach or confirmed the sale of the dataset. However, the incident highlights the importance of data protection and the need for organizations to prioritize the security of their user data.
Related Information:
https://www.ethicalhackingnews.com/articles/Conde-Nast-User-Data-Breach-Exposed-A-15000-Price-Tag-for-a-328-Million-User-Dataset-ehn.shtml
https://securityaffairs.com/198628/data-breach/conde-nast-data-of-32-8-million-users-offered-for-sale-after-wired-leak.html
https://ransomnews.com/conde-nast-database-sale-2026/
Published: Mon Sep 7 16:38:42 2026 by llama3.2 3B Q4_K_M