{"id":9525,"date":"2025-12-29T10:03:37","date_gmt":"2025-12-29T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/29\/hackers-claim-breach-of-wired-database-containing-2-3-million-subscriber-records\/"},"modified":"2025-12-29T10:03:37","modified_gmt":"2025-12-29T10:03:37","slug":"hackers-claim-breach-of-wired-database-containing-2-3-million-subscriber-records","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/29\/hackers-claim-breach-of-wired-database-containing-2-3-million-subscriber-records\/","title":{"rendered":"Hackers Claim Breach of WIRED Database Containing 2.3 million Subscriber Records"},"content":{"rendered":"<p>    Hackers Claim Breach of WIRED Database Containing 2.3 million Subscriber Records<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Hackers have leaked a database containing over 2.3 million WIRED subscriber records, marking a major breach at Cond\u00e9 Nast, the parent company.<\/p>\n<p>The threat actor \u201cLovely\u201d claims this is just the start, promising to release up to 40 million more records from brands like Vogue and The New Yorker.<a href=\"https:\/\/securityaffairs.com\/186224\/data-breach\/conde-nast-faces-major-data-breach-2-3m-wired-records-leaked-40m-more-at-risk.html\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\u200b<\/p>\n<p>The data dump, posted on hacking forums like Breach Stars and BreachForums around Christmas Day 2025, includes 2.3 million email addresses, 285,936 names, 102,479 home addresses, and 32,426 phone numbers.<\/p>\n<p>Records feature JSON-formatted profiles with fields like user IDs, creation dates from 2011 to 2022, and recent activity up to September 8, 2025. Screenshots from the leak show extensive file lists and redacted subscriber details across Cond\u00e9 Nast sites.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/images\/11146061\/6bf2d942-5212-44b8-858f-a2e3948dfdcd\/wired2.jpg?AWSAccessKeyId=ASIA2F3EMEYEXY4X6YYW&amp;Signature=RA%2BLhsmBUpTpO67IOt8d1e9haDM%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEMr%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIDXOmKh%2BrmvrjOm4Ihi7lgk5NcC%2FqGgEgQhiyv8tJRU2AiEAnK3WL3ty8x95CcXhd3lqSyaMM8JAkv8or3K1WWWngp4q%2FAQIk%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDEJAkoY1l7zfVfUj0CrQBC7SU64Ukam%2Bu6KoCWBLfjkEgQal74sWEwwW94fh7n9i5AVijowVlq52ewzbAuF%2BnQs75SxniMyCZciSiFKWqrkzX0SIDhHKnamjceHeewwGG%2F59Mp7FMcCgbjXmB2TIcCPGophRqN0AvRnFbLYHGox5wTCYW4Tz3rG%2BjLQ%2B23F%2BjhdTenqMiW%2BxZl%2BDrJ%2FgnxZe4GWbBOwysYAVhskMY4F1xYzF3b%2Fi8O6Nc%2FfFpyQ0OTOnnScrekoy%2F2FNzTHHMLPqBo8Iuask4bUmqqzu9dyTZjiRjo2u%2B8uGuOn%2BZRnF4hMODE4QH27CLea8vgcG7%2Flhire0%2FAEJgQvAZodjjfBAYZ1mE4H6TJmWo7G0wmhb5F%2FQSQc2Jug7Vr0s1O63%2BdVdE7GT0KBchnlPn0P5YwIaKKl60vfW7qiCYEnZxFfPcBq4SnhAmEmQOm4Vjanp1H32wb756s87%2BvExUfHmmU995TGf96p4O4kbro86GxvkWx%2Fqs%2FGa08LoPZGgPuQ7xVP6HPdlb5ggnEE3vf30CzKAXIhkL%2Fe0odcL6kgGRRf%2BdNnY4Cr5wRv%2BOEbvoZ1Z%2BGlozAdUJcmHWf2jl7aDswQly4Q0UYgEm6b3Ti74D4Y1B14j7AkFmThtA5s6UNMaCSx7juz3d7o2fReIGd5UAAZuLcKDyZr7t%2Bvtiu2IJJcOF6T%2BEDL6VaWaNOd8WqLdP80NPVmKRJjeKvwCoLjjBbNmIEV0KucBWoKZyF1xIFfON5bMq1A2FBVC44Bm10%2FnRv1ysgnq3kVhReRbRRUBNxAwwL%2FHygY6mAFViU7kNTYj3U%2BK97D9T6nX9o90vRI%2FZrodgr%2FMUQSLAdfQ1%2BO1dhbwmYpxgYNQ4%2Fj0BKWUdfGxfcq8VxVGBnvari1HZDyfUaLJRuw9lGWlJu%2FUKhIaUkzD063H6Rcab646WcAYVrrPqUz8AEnGR0c7aOex45UsWFXbk7%2BhxpjPDNSX%2B6iTyEACS40r6tn%2FP3qecSZgVsBpxA%3D%3D&amp;Expires=1766975939\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\u200b<\/p>\n<p>Hudson Rock researchers <a href=\"https:\/\/www.infostealers.com\/article\/wired-database-leaked-40-million-record-threat-looms-for-conde-nast\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">verified<\/a> the WIRED data\u2019s legitimacy by cross-referencing it with RedLine and <a href=\"https:\/\/cybersecuritynews.com\/raccoon-infostealer-admin-arrested\/\" target=\"_blank\" rel=\"noreferrer noopener\">Raccoon infostealer<\/a> logs, confirming high-overlap compromised credentials.<\/p>\n<p>The firm warns of a looming 40-million-line breach targeting Cond\u00e9 Nast\u2019s shared identity system, which spans publications including Vanity Fair, GQ, and Architectural Digest. No passwords or payment info appeared in the initial dump, but PII exposure raises risks for phishing, doxing, and swatting.<a href=\"https:\/\/cyberinsider.com\/2-3-million-alleged-wired-subscriber-records-leaked-on-breachforums\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\u200b<\/p>\n<p>Attackers exploited Insecure Direct Object References (IDOR) to scrape profiles by iterating through user IDs, resulting in large JSON exports.<\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/coursera-api-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener\">Broken access controls<\/a> on account endpoints enabled unauthenticated access to and modification of emails, passwords, and profiles. These flaws in the centralized platform enabled bulk exfiltration without full authentication.<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hacker-claims-to-leak-wired-database-with-23-million-records\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\u200b<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Data Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Count<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Emails<\/td>\n<td>2,300,000<\/td>\n<\/tr>\n<tr>\n<td>Names<\/td>\n<td>285,936<\/td>\n<\/tr>\n<tr>\n<td>Addresses<\/td>\n<td>102,479<\/td>\n<\/tr>\n<tr>\n<td>Phone Numbers<\/td>\n<td>32,426<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>In November 2025, \u201cLovely\u201d posed as a researcher, \u201cDissent Doe,\u201d and <a href=\"https:\/\/databreaches.net\/2025\/12\/25\/conde-nast-gets-hacked-and-databreaches-gets-played-christmas-lump-of-coal-edition\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">contacted<\/a> DataBreaches.net to help notify Cond\u00e9 Nast of six vulnerabilities.<\/p>\n<p>Despite repeated outreach, including via WIRED reporters and security teams, Cond\u00e9 Nast offered no public response or security.txt file. Frustrated, Lovely leaked the WIRED data as a \u201cChristmas Lump of Coal,\u201d accusing the firm of ignoring users.<a href=\"https:\/\/databreaches.net\/2025\/12\/25\/conde-nast-gets-hacked-and-databreaches-gets-played-christmas-lump-of-coal-edition\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\u200b<\/p>\n<p>Affected subscribers report hits on dark web monitors like Have I Been Pwned, which <a href=\"https:\/\/haveibeenpwned.com\/Breach\/WIRED\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">added<\/a> the breach. Cond\u00e9 Nast\u2019s silence amplifies risks, as shared logins could cascade across brands. Experts urge password resets and monitoring, highlighting the need for better vulnerability disclosure in media giants.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/wired-database-breach\/\">Hackers Claim Breach of WIRED Database Containing 2.3 million Subscriber Records<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/wired-database-breach\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Claim Breach of WIRED Database Containing 2.3 million Subscriber Records Hackers have leaked a database containing over 2.3 million WIRED subscriber records, marking a major breach at Cond\u00e9 Nast, the parent company. The threat actor \u201cLovely\u201d claims this is just the start, promising to release up to 40 million more records from brands like [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-9525","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9525"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9525"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9525\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}