HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Condé Nast Exposes 32.8 Million User Records for Sale After WIRED Leak

A 32.8 million‑record user database from Condé Nast appeared on a Russian cybercrime forum, confirming a data‑exfiltration incident. The exposure of personal identifiers highlights the need for documented privacy controls and continuous monitoring to satisfy audit‑readiness requirements.

Verisq™ Intelligence · 📅 September 09, 2026 · 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

Condé Nast Exposes 32.8 Million User Records for Sale After WIRED Leak

What Happened — A database containing 32.8 million Condé Nast user records was listed for $15,000 on a Russian‑language cybercrime forum. A 5,000‑record sample verified that the data matches accounts collected between September and October 2025, including fields that have not been publicly disclosed before. Condé Nast has not publicly confirmed the breach.

Why It Matters for Trust & Control Assurance

  • The exposure tests the robustness of data‑classification, handling, and monitoring controls that a continuous assurance program must evidence.
  • Demonstrating documented privacy‑governance (consent, minimisation, data‑subject request handling) provides a defensible audit trail under GDPR‑style regulations.
  • Leveraging a privacy‑focused control‑assurance capability (CookiePLUS) helps prove that personal data is protected, logged, and that any exposure can be quickly identified and reported.

Who Is Affected — Media & publishing organisations, their subscribers, and downstream advertisers that rely on those user profiles.

Recommended Actions

  • Activate your breach‑response playbook and confirm the full scope of compromised records.
  • Update your data‑inventory and map the exposed fields to privacy‑control objectives (consent, data minimisation, retention).
  • Strengthen continuous monitoring for anomalous data‑exfiltration and ensure evidence collection for audit readiness.
  • Review and, if needed, revise privacy notices and DSAR processes.

Source: SecurityAffairs

Technical Notes — The offered dataset includes email addresses, names, postal addresses, gender, dates of birth and phone numbers; no passwords, password hashes, usernames or payment‑card data were found. The sale appears on a Russian‑language forum; the original leak was reported in December 2025. Source: SecurityAffairs

📰 Original Source
https://securityaffairs.com/198628/data-breach/conde-nast-data-of-32-8-million-users-offered-for-sale-after-wired-leak.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →