Drooid Logo
Back to story perspectives

Full Breakdown

Major Data Breach Exposes Personal Information of Wired.com Users

12/28/2025, 11:42:43 PM

Overview of the Breach

On December 20, 2025, a hacker using the alias "Lovely" leaked personal data of over 2.3 million users from Wired.com, a prominent publication owned by Condé Nast. The breach was announced on the newly launched hacking forum, Breach Stars, where the hacker accused Condé Nast of neglecting security vulnerabilities. The leaked data includes user records containing full names, email addresses, user IDs, and timestamps related to account creation and updates, but notably lacks password or payment information.

Scope of the Data Leak

The hacker claims that the breach is part of a larger attack on Condé Nast, threatening to release data from up to 40 million accounts across various brands, including Vogue, GQ, and The New Yorker. The leaked Wired.com dataset reportedly includes records dating back to 2011, indicating that the data was extracted from a live or archived user database rather than a static marketing list. The hacker's message suggested that they had direct access to Condé Nast's account management systems.

Data Characteristics

The leaked records feature a mix of personal and system-generated email addresses, with many entries showing empty fields for personal information like phone numbers and birthdays. The dataset includes approximately 3 million email addresses, 285,936 full names, 102,479 home addresses, and 32,426 phone numbers. The presence of real user accounts raises significant privacy concerns, as the data could be exploited for doxing, spear-phishing, or other malicious activities.

Official Responses and Verification

As of now, Condé Nast has not publicly confirmed or denied the breach. Attempts to verify the authenticity of the leaked data have been made by cybersecurity firm Hudson Rock, which confirmed the legitimacy of the records by cross-referencing them with previously compromised credentials from malware infections. Despite the lack of an official response from Condé Nast, reports from users on platforms like Reddit have corroborated the breach, with some subscribers receiving alerts from digital footprint scanners.

Criticism of Condé Nast's Security Practices

The hacker's claims highlight alleged failures in Condé Nast's security protocols. They stated, "Condé Nast does not care about the security of their users’ data," emphasizing that it took a month of warnings before any action was taken to address vulnerabilities. Security researchers have pointed to multiple underlying issues, including Insecure Direct Object References (IDOR) and broken access controls, as potential avenues exploited by the hacker to access user data.

Implications and Future Risks

The potential release of an additional 40 million records poses serious risks to users, as it could facilitate targeted attacks leveraging the context of Condé Nast's brands. The implications of such a breach extend beyond privacy violations, raising concerns about physical threats and the safety of individuals whose information may be exposed.

Verbatim Quotes

  • “Condé Nast does not care about the security of their users’ data. It took us an entire month to convince them to fix the vulnerabilities on their websites. We will leak more of their users’ data (40+ million) over the next few weeks. Enjoy!” — Lovely, Hacker
  • “Our validation of the current data confirms it is legitimate and fresh, with entries as recent as September 8, 2025.” — Alon Gal, Co-founder of Hudson Rock

As investigations continue, the full extent of the breach and its impact on users remains to be seen.