A trove of 32.8 million alleged Conde Nast reader records is up for sale, and the details matter more than the headline
A dataset said to hold roughly 32.8 million records tied to Vogue, The New Yorker, GQ, WIRED and other Conde Nast titles was listed on a cybercrime forum for $15,000. It is alleged, not confirmed, the count is records not people, and it reportedly contains no passwords or card numbers. Here is what is actually being claimed, what a researcher checked, and why it still matters.

A dataset said to contain 32,815,767 records tied to Conde Nast reader accounts, spanning Vogue, The New Yorker, GQ, WIRED, Vanity Fair and other titles, was offered for sale on a cybercrime forum around 7 September 2026 for $15,000. Everything here is alleged: it is a forum listing plus a partial researcher check, not a breach Conde Nast has confirmed, and the company has not commented. The count is a tally of records and unique emails, not verified people, and reporting says it contains no passwords, hashes or payment-card data. The realistic risk is targeted phishing, not account takeover. Here is the careful version.
Breach headlines love a big round number, and "33 million" is doing a lot of work in this one. A dataset attributed to readers of some of the most recognisable magazines in the world has been put up for sale, and it is easy to turn that into "33 million people hacked." The reality is more bounded and more interesting: it is an unconfirmed listing, the number counts rows rather than humans, the most sensitive fields are reportedly sparse, and there are reportedly no passwords in it at all. If the data is genuine, the risk it poses is a phishing one, not a stolen-wallet one. Here is what the evidence actually supports.
What happened?
Around 7 September 2026, a seller on a cybercrime forum listed a dataset attributed to Conde Nast reader accounts, asking $15,000 for it. Security outlets including SecurityAffairs and eSecurity Planet reported the listing, which named brands such as Vogue, The New Yorker, GQ, Glamour, WIRED and Vanity Fair. A second, smaller bundle of about 30.46 million records (the same set with WIRED accounts removed) was also offered.
The most important word is alleged. This is a forum offer plus an outside researcher's partial review, not a breach that Conde Nast has disclosed or confirmed. As of writing, the company has not commented on the listing, and its silence is not an admission of anything.
Does this mean 32.8 million people?
Fewer than the headline implies, and the honest answer is that nobody knows. The listing cites 32,815,767 records, described as unique email addresses. That is the size of the file, not a verified count of distinct people. One person can hold several email addresses, and some rows are role-based or shared inboxes rather than individuals, so the number of unique emails can exceed the number of distinct people. The accurate phrasing is therefore "32.8 million records" or "accounts," never "32.8 million readers affected."
What is in the data, and what is not?
This is where the risk gets its real shape. Per the reporting on the listing, the fields are mostly sparse:
- Email address: in 100% of rows.
- First and last name: about 31.6%.
- Postal address: about 22.3%.
- Gender: about 17.5%.
- Date of birth: about 12.6%.
- Phone number: about 2.9%.
Crucially, the dataset reportedly contains no passwords, password hashes, usernames or payment-card data. That single fact reshapes the whole story: it would mean no credential dump and no direct route to draining an account. Most rows are an email plus a magazine association, with a minority carrying a real name and home address.
Is it actually real?
Only partially checked, and worth stating precisely. The cybersecurity outlet Ransomnews reviewed a 5,000-row sample and found it internally consistent with genuine Conde Nast account data, with the seller's stated field-completion rates matching to within 1.2 percentage points. But this was an internal-consistency review, not a validation against live accounts (which the researchers avoided to prevent privacy harm). A 5,000-row check does not verify all 32.8 million rows.
There is one suggestive link. The listing's implied WIRED portion of around 2.36 million closely matches the 2,366,576 WIRED subscriber records that were leaked publicly in December 2025. That alignment is a reason to take the set seriously, but it is not proof that the September seller is the same person, or that the fuller 32.8 million is genuine. Most of the records, around 30.5 million, have reportedly not circulated publicly before.
How old is the data?
Old enough to matter. Account-creation dates in the set reportedly run from 1999 to 23 October 2025, and the collection window is described as roughly September to late October 2025. So even if the data is authentic, it is close to a year old. That cuts both ways: phone numbers and addresses go stale as people move, but emails and names change slowly, so the phishing value persists.
If there are no passwords, why does it matter?
Because the danger here is not account takeover, it is targeted social engineering. An email address, a real name, a home address and a known interest in a specific magazine are exactly the ingredients for convincing, tailored phishing and postal scams. As eSecurity Planet put it, tying "real names and physical home addresses to specific cultural interests" lets bad actors build "sophisticated, hyper-targeted spear-phishing and mail-fraud schemes." A fake "subscription renewal" email that knows which titles you read is far more persuasive than a generic one.
What should readers do?
Nothing dramatic, and there is no password-reset emergency here because no passwords were reportedly exposed. Sensible steps:
- Treat unexpected emails or post referencing these magazines with extra caution, especially anything about subscriptions, renewals or payment.
- Never click links in unsolicited "renewal" or "account" messages. Go to the publisher's site directly.
- Keep up good general hygiene anyway: unique passwords and multi-factor authentication on important accounts.
- You can check Have I Been Pwned for the earlier WIRED dataset.
Alleged vs established
| Claim | Status |
|---|---|
| 32,815,767 records offered on a cybercrime forum for $15,000 | Reported from the listing, unconfirmed by Conde Nast |
| 32.8 million = records / unique emails, not verified people | The accurate reading |
| No passwords, hashes or payment-card data | Reported from the listing |
| Sample checked as internally consistent | Researcher review of 5,000 of ~32.8M rows only |
| Matches the December 2025 WIRED leak (2.36M) | Suggestive, not proof of the same seller or full authenticity |
| Data collected by late October 2025 | Aged, close to a year old |
| Conde Nast breached 32.8 million readers | NOT established; company has not commented |





