Data breach
Wired.com
- Records
- 2,366,317
- Breach date
- 8 October 2025Estimated
- Added
- 28 December 2025
What was exposed
4 types of data · 3 more reported
- Email addresses1
- Names1
- Home addresses1
- Phone numbers1
- Dates of birthReported, not counted
- GenderReported, not counted
- UsernamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
A large dataset of Wired.com subscriber records surfaced on cybercrime forums in late December 2025. According to our investigation team, the listing contains 2,366,317 records, and the breach is estimated to have occurred on or around October 8, 2025. Security researchers at Hudson Rock, an Israeli cybersecurity firm, authenticated the data by matching records against credentials previously stolen by info-stealer malware, and the most recent entries in the files date to September 8, 2025.
A hacker using the alias "Lovely" posted the database on the Breach Stars forum, offering it for roughly $2.30 in forum credits before it was later reposted for free. The hacker claims the Wired data is only a sample from a much larger compromise of the centralized account system run by Condé Nast, Wired's parent company, and has threatened to release more than 40 million additional records tied to publications such as Vogue, The New Yorker, and Vanity Fair. Researchers cited in reporting by SecurityAffairs believe the attacker exploited insecure direct object reference (IDOR) flaws and broken access controls, which would have allowed unauthorized users to view other people's account profiles. Condé Nast and Wired did not respond to a request for comment from SecurityWeek.
Breach Timeline
December 20, 2025: A hacker known as "Lovely" posted a database titled "2.3M wired.com Database" on the Breach Stars cybercrime forum, linking to an archive of roughly 2.366 million records, according to BrightDefense.
December 26, 2025: A forum moderator reposted the same dataset, making it freely downloadable.
December 28, 2025: BleepingComputer and other security outlets reported on the leak and the hacker's threat to publish up to 40 million additional Condé Nast records.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, phone numbers, names, and home addresses.
Reporting based on analysis of the leaked files indicates email addresses appear in every record, while names, dates of birth, physical addresses, phone numbers, and genders were present for only a small share of users. The dataset also included display names, user IDs, and account timestamps, with registrations dating back to 2011. No passwords or payment card information were found in the leak.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because the leaked data centers on email addresses and, for some people, home addresses and phone numbers, the most immediate risk is phishing. Scammers can use a subscriber's real email address and account details to send convincing messages that appear tied to a legitimate publication or subscription.
People whose home addresses or phone numbers were exposed face a higher risk of targeted fraud attempts, unwanted solicitation, and, in rare cases, physical-targeted scams such as fake delivery notices. The exposure of names, birthdates, and addresses can also support identity fraud when combined with other leaked data.
The absence of passwords in the dataset lowers the risk of direct account takeover through credential stuffing. However, anyone who reused a Wired password elsewhere should still treat that habit as a liability.
What Is Wired.com Doing in Response?
As of early January 2026, neither Condé Nast nor Wired had issued a public statement acknowledging the breach, according to BrightDefense, and SecurityWeek reported the company did not respond to its request for comment. No confirmed notifications to affected subscribers have been verified in our review.
What Should You Do If You Were Affected?
Be cautious with emails or texts claiming to come from Wired, Condé Nast, or any subscription service. Avoid clicking links or opening attachments in unexpected messages.
If you have a Wired or Condé Nast account, change your password and enable two-factor authentication where available.
Do not reuse the same password across multiple sites.
Watch your financial accounts and credit reports for unusual activity, especially if your home address or phone number was part of the leak.
Treat any caller or message claiming knowledge of your subscription details with suspicion. Knowing your email address alone does not make someone a legitimate representative.
In the news
- SecurityWeek: Hacker Claims Theft of 40 Million Condé Nast Records After Wired Data Leaksecurityweek.com (opens in a new tab)
- SecurityAffairs: Condé Nast faces major data breachsecurityaffairs.com (opens in a new tab)
- BrightDefense: 2.3M WIRED Subscribers Exposed in Condé Nast Leakbrightdefense.com (opens in a new tab)
- Cybernews: New Yorker, Vogue, and WIRED accounts may be breachedcybernews.com (opens in a new tab)
