Hacker claims breach of Condé Nast user database

A hacker using the name Lovely has claimed responsibility for breaching a Condé Nast user database, releasing over 2.3 million records from WIRED magazine. The data includes personal details like names, emails, addresses, and phone numbers, but no passwords. The hacker threatens to leak an additional 40 million records from other Condé Nast publications in the coming weeks.

Earlier in December 2025, the hacker Lovely announced the breach of a Condé Nast user database. They released a dataset containing more than 2.3 million user records specifically from WIRED, one of Condé Nast's prominent publications. The exposed information encompasses basic demographic details such as names, email addresses, physical addresses, and phone numbers, though crucially, it does not include passwords.

Lovely has indicated plans to disclose further data affecting up to 40 million users across various Condé Nast titles, including Vogue, The New Yorker, and Vanity Fair. However, Ars Technica, another publication under the broader umbrella but operating independently, remains unaffected due to its unique technical infrastructure.

The hacker portrayed their actions as a response to Condé Nast's alleged neglect of security vulnerabilities. In a statement, Lovely wrote: “Condé Nast does not care about the security of their users data. It took us an entire month to convince them to fix the vulnerabilities on their websites. We will leak more of their users’ data (40 + million) over the next few weeks. Enjoy!”

Questions surround the hacker's true intentions. According to DataBreaches.Net, Lovely initially posed as someone assisting with vulnerability patches but was actually seeking financial gain. The site stated: “As for “Lovely,” they played me. Condé Nast should never pay them a dime, and no one else should ever, as their word clearly cannot be trusted.”

Condé Nast has yet to release an official statement on the incident. Ars Technica reports no internal notification, which aligns with their separation from the affected systems. Security researchers, such as those at Hudson Rock’s InfoStealers, have provided detailed analyses of the leaked data's scope.

संबंधित लेख

A hacker known as Rootboy has begun daily data dumps from Standard Bank's systems on the dark web since 14 April, following the bank's refusal to pay a 1 Bitcoin ransom. The attack, which started on 27 February, exfiltrated 1.2TB of data from Standard Bank and Liberty. The bank has confirmed exposure of some credit card details but no CVV numbers.

AI द्वारा रिपोर्ट किया गया

Nintendo has confirmed that data was stolen during a cyberattack involving a third party. The company noted that no significant secrets were revealed in the breach. A group identifying itself as Shadowbyt3$ is demanding $2 million for the stolen data.

Tata Electronics has confirmed a data breach after hackers claimed to have stolen a large database containing files related to Apple and Tesla.

AI द्वारा रिपोर्ट किया गया

A cyberattack targeted Vivaticket, the ticketing system used by major museums such as the Louvre and Uffizi Galleries. The RansomHouse hacking group has claimed responsibility for the incident. Uffizi officials confirmed the attack but stated that no data was ultimately stolen.

यह वेबसाइट कुकीज़ का उपयोग करती है

हम अपनी साइट को बेहतर बनाने के लिए विश्लेषण के लिए कुकीज़ का उपयोग करते हैं। अधिक जानकारी के लिए हमारी गोपनीयता नीति पढ़ें।
अस्वीकार करें