32.8 million Condé Nast accounts, offered for $15,000
The WIRED leak last December was the small end of it. The full set covers readers of Vogue, The New Yorker, GQ, Glamour and Vanity Fair, and a sample has been checked as genuine. Here is what is in it, what is not, and what to do if you have an account.
On 7 September 2026 a seller listed 32,815,767 Condé Nast user records for $15,000 on a cybercrime forum. A check of a 5,000-record sample found it genuine, collected in September and October 2025. About 2.36 million of the records are the WIRED accounts leaked in December 2025; the other 30.5 million, from titles such as Vogue, The New Yorker and GQ, have never been public. Every record has an email, some have names, postal addresses and dates of birth, and none of the sample held passwords or card details. Condé Nast has said nothing. Expect targeted renewal and payment scams, not account takeovers.
What happened, in order
Nine months between the first leak and the sale. Everything here comes from the people selling or analysing the data. The company has not confirmed or denied any of it.
| When | What happened |
|---|---|
| September–October 2025 | The period the records date from, according to an analysis of a sample of the data. |
| December 2025 | Someone using the name “Lovely” publishes 2,366,576 WIRED account records and says more than 40 million Condé Nast records sit behind them. Condé Nast does not comment. |
| Late December 2025 | The WIRED set is indexed by public breach databases at 2,364,431 email addresses. |
| 7 September 2026 | A seller on a Russian-language cybercrime forum lists 32,815,767 unique Condé Nast email records for $15,000, and separately offers a version without WIRED: 30,455,594 records. |
| 7–8 September 2026 | Ransomnews checks a 5,000-row sample and finds it consistent with genuine account data, including records never published before. Security Affairs and Cybernews report the sale. |
| 19 September 2026 | Condé Nast still has not said anything publicly. The 30.5 million non-WIRED records have not been published, and no public breach database holds them. |
What the records contain
Shares of each field in the 5,000-record sample that was checked. The seller’s own description matched these figures to within 1.2 percentage points.
| Field | Share of records |
|---|---|
| Email address | Every record |
| First and last name | 31.6% |
| Postal address | 22.3% |
| Gender | 17.5% |
| Date of birth | 12.6% |
| Phone number | 2.9% |
| Passwords, password hashes, payment cards | None found |
Sources: Ransomnews sample analysis and Security Affairs, 7 September 2026; Cybernews, 8 September 2026; SecurityWeek and BleepingComputer on the December 2025 WIRED leak. Condé Nast has published no statement on either.
1. Why the WIRED leak was only the first 7%
In December 2025 someone released 2,366,576 WIRED account records and said they had more than 40 million Condé Nast records behind them. The company never responded, and the claim sat unverified for nine months. The listing that appeared on 7 September 2026 answers most of it: 32,815,767 unique email addresses, with WIRED making up about 2.36 million of them and a separate offer for the 30,455,594 records from everywhere else. That makes the published WIRED set roughly 7% of the whole. The other 93%, which covers readers of the rest of the portfolio, has never been public, and it is the part that is new.
2. Which magazines are involved
Condé Nast runs one account system across its titles, which is how a single database can hold readers of several magazines at once. Coverage of the sale names Vogue, The New Yorker, GQ, Glamour, Vanity Fair and WIRED, and the portfolio also includes titles such as Architectural Digest, Bon Appétit, Condé Nast Traveler and Allure. Nobody has published a breakdown by title, so it is not possible to say how many records belong to each. The practical rule is simple: if you created an account at any Condé Nast site before late October 2025, to read past a paywall, manage a subscription, comment or sign up for a newsletter, you may be in it.
3. What one record holds
Less than the headline number suggests, and more than an email address. Every record has an email; about one in three has a full name, about one in five has a postal address, and smaller shares carry gender, date of birth and phone number. The sample held no passwords and no payment details. That changes what the risk is. Nobody can sign in to your account with this, but anyone who buys it knows which magazines you read, and often where you live, which is everything a convincing renewal notice or “payment failed” email needs.
4. The honest answer to “am I in it”
Only partly answerable. The WIRED records were published, so the known breach databases hold them, and a free check will tell you whether your email is among them. The other 30.5 million records have only been offered for sale. They are not indexed anywhere, and there is nothing to search. Condé Nast could tell you what it holds on you if you ask through its privacy request process, but it has not said which accounts were taken, and it may never send a notice, because contact details alone often fall below the threshold that US breach laws set for telling people.
5. What to do if you have a Condé Nast account
Treat any email about your subscription as suspect for the next few months, and manage the subscription by typing the magazine’s address into your browser rather than clicking through. Check the WIRED part of the leak against your email. Close accounts at titles you no longer read, and send Condé Nast a deletion request for the rest if you do not need them. If you reused the Condé Nast password elsewhere, change it there anyway: the sample held no passwords, but nobody outside the sale has seen the full set. For future sign-ups, a separate or masked email address per subscription makes the next leak of this kind traceable and easy to cut off.
6. The scams this data is built for
Magazine subscribers have been the target of fake renewal notices for decades: official-looking letters from third parties offering to renew at a high price, or bills for subscriptions that are not due. A list that pairs a reader’s email and postal address with the titles they read makes those notices easy to aim, by post and by email. Expect messages saying your payment failed, your subscription is about to lapse, or you have been chosen for a free issue, each with a link. The magazine will show your real renewal date inside your account. A letter or email that does not match it is not from them.
7. The part that outlives the sale
A name, email and home address sold in one place tend to end up everywhere: merged into marketing lists, then into people-search profiles that sit next to your phone number and relatives. That is the part of this you can still shrink, and it needs repeating, because listings return. Our post-breach guide covers the order of the other steps, and the WIRED breach page has the details of the part that was published in December.
A postal address on a sold list rarely stays on one list
Your name and home address are probably already published next to your phone number and relatives on 499 broker and people-search sites. PersProtect finds where you appear, files the removals and keeps checking. The scan is free.
Check my exposure — free →The Condé Nast breach, answered
Was Vogue hacked?
Condé Nast’s account data was, according to the seller and to an independent check of a sample, and Vogue is one of the titles that runs on it. Nobody has shown that Vogue’s own site was broken into, and the company has not confirmed anything. The accurate version is that a database of 32.8 million Condé Nast user records, covering readers of Vogue, The New Yorker, GQ, Glamour, Vanity Fair and WIRED among others, is being sold, and a sample of it checks out as real.
Were passwords stolen?
Not according to the sample analysis. The 5,000 records that were checked contained email addresses, and some names, postal addresses, genders, dates of birth and phone numbers, but no passwords, password hashes or payment card details. Changing your Condé Nast password will not hurt, but it does not address what actually leaked, which is contact information that makes a convincing phishing email or a fake renewal notice easy to write.
Is this the same as the WIRED breach from December?
It is the rest of it. In December 2025 about 2.37 million WIRED records were published, and whoever released them said there were more than 40 million Condé Nast records in total. The set now for sale contains the WIRED records plus 30.5 million from the other titles, which is why the seller also offers a version without WIRED. If you were in the December leak you are almost certainly in this one too. If you were not, you may still be, through another magazine.
How do I check whether my account is in it?
For WIRED accounts you can check now, because that part was published and is held by the known breach databases, including the ones our free check uses. For every other Condé Nast title there is no way to check yet: the data is being sold rather than posted, and nothing indexes it. If it is ever dumped publicly, those databases will pick it up. Until then, anyone offering to tell you whether your Vogue or New Yorker account is in the sale is guessing, or collecting emails.
Will Condé Nast notify me?
Possibly not. The company has not commented on either leak, and most US state breach laws require a notice only when specific data is involved, such as a Social Security number, a driver’s license number, a financial account, or an email address together with a password. An email with a name and a postal address, which is what most of these records hold, often does not meet that bar. Waiting for a letter is not a plan here.
I only get the print magazine. Could I be in it?
Less likely, but nobody has said. The records are described as online account data, the kind created when you register on a Condé Nast site to read, comment, manage a subscription or sign up for a newsletter. A print-only subscription handled entirely by mail may sit in a different system. If you have ever logged in to manage your subscription online, assume you have an account.
Should I cancel my subscription?
There is no need to, and cancelling does not remove records that were collected in 2025. What does help is closing accounts at titles you no longer read, and asking Condé Nast, through its privacy request process, to delete the data it holds on you. That will not recall a copy that is already for sale, but it shrinks whatever might be taken next time.
They know what you read. Limit what else they know.
See which sites list your name, address and relatives right now — free, in about a minute.
Run my free exposure scan →