Condé Nast A.I CyberSecurity Scoring
Condé Nast
Company Information
Website:http://www.condenast.com
Employees number:7,095
Number of followers:804,370
NAICS:51211
Industry Type:Media Production
Homepage:condenast.com
Condé Nast Risk Score (AI oriented)
Between 600 and 649
Condé NastMedia Production
Updated:
07/09/2026
07/09/2026
647/1000
Poor
Caa
Condé Nast Global Score (TPRM)
xxxx
Condé NastMedia Production
Score locked

Condé NastPoor
Current Score
647Caa (POOR)
01000
3 incidents
-73 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
649
SEPTEMBER 2026
718
Breach
07 Sep 2026 • Condé Nast
Condé Nast, Vogue, GQ, Glamour, WIRED and Vanity Fair: Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak
Condé Nast Data Breach Exposes 32.8 Million User Records for Sale
647
CRITICAL-71
GLAWIRGQ-CONVOG1788812814
Condé Nast Data Breach Exposes 32.8 Million User Records for Sale
A database containing 32.8 million Condé Nast user records is being sold for $15,000 on a Russian-language cybercrime forum, following a leak initially tied to the company’s WIRED publication in December 2025. Cybersecurity outlet Ransomnews verified a 5,000-record sample, confirming its authenticity as genuine Condé Nast account data collected between September and October 2025 including 30.5 million records never previously disclosed.
The dataset spans users across Condé Nast’s portfolio, including Vogue, The New Yorker, GQ, Glamour, Vanity Fair, and WIRED. While it lacks passwords, payment details, or usernames, it includes email addresses (100% of records), names (31.6%), postal addresses (22.3%), gender (17.5%), dates of birth (12.6%), and phone numbers (2.9%). The seller claims the full dataset underpins the earlier WIRED leak, with a separate version excluding WIRED containing 30.4 million records aligning with the 2.36 million WIRED records released in 2025.
Ransomnews’ analysis found the sample structurally distinct from the public WIRED leak, with higher rates of names and addresses, suggesting a broader collection across Condé Nast’s consumer titles. Internal consistency checks such as matching email patterns to names, ZIP code accuracy, and realistic web-form errors supported its legitimacy. Account creation dates range from 1999 to October 2025, with a sharp decline in new entries after September 2025, indicating the breach likely occurred over several weeks that fall.
The attack vector appears linked to insecure direct object reference (IDOR) vulnerabilities, where improper access controls allowed unauthorized data extraction. The seller, operating under a low-reputation account with escrow services, is likely targeting a single buyer rather than a public dump. While the absence of passwords limits immediate credential-stuffing risks, the data enables highly targeted phishing, fraud, and scams particularly for subscription-based services, where attackers could craft convincing fake renewal or billing requests using real user details.
The incident underscores the evolving economics of data breaches, where attackers may release a small, recognizable subset to validate a larger, private sale balancing public notoriety with monetization. Condé Nast has not publicly confirmed the breach.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
716
JULY 2026
714
JUNE 2026
714
MAY 2026
711
APRIL 2026
711
MARCH 2026
708
FEBRUARY 2026
707
JANUARY 2026
706
DECEMBER 2025
779
Breach
20 Dec 2025 • Condé Nast
GQ, Condé Nast, Vogue, Wired, Self, Glamour, Vanity Fair, Teen Vogue and Condé Nast Traveler: Hacker Leaks 2.3M Wired.com Records, Claims 40M-User Condé Nast Breach
Wired.com User Data Leak by Hacker 'Lovely'
704
CRITICAL-75
GQ-CONCONWIRSELGLACONCONCON1766865597
Cybersecurity Alert: Hacker Leaks Data of 2.3 Million Wired.com Users, Claims Larger Condé Nast Breach
On December 20, 2025, a hacker operating under the alias "Lovely" leaked what they claim is the personal data of over 2.3 million Wired.com users on the newly launched hacking forum Breach Stars. The leaked dataset includes full names, email addresses, user IDs, display names, account creation timestamps, and in some cases, last session dates—though no passwords or payment information were exposed. The data spans accounts created between 2011 and 2022, with some records showing recent activity, suggesting a breach of a live or archived user database.
The hacker accused Condé Nast, Wired’s parent company, of neglecting security warnings, stating they had spent a month attempting to alert the company before resorting to the leak. In a provocative message, they threatened to release data from over 40 million additional accounts across Condé Nast’s portfolio in the coming weeks. The leaked breakdown includes records from brands such as GQ (994K), Vogue (1.9M), The New Yorker (6.8M), and Bon Appétit (2M), among others. An entry labeled "NIL" with 9.5 million accounts remains unidentified, while smaller segments suggest the breach may involve centralized account infrastructure.
Prior to the leak, the hacker had contacted journalists, including DataBreaches.net, posing as a security researcher before shifting to threats of public exposure. The method of the breach remains undisclosed, though analysis by Hackread.com confirms the legitimacy of the leaked Wired data. Condé Nast has yet to issue a public statement confirming or denying the incident. Until an official response is provided, the claims and leaked data remain unverified.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
779
MAY 2019
790
Breach
01 May 2019 • Condé Nast
Condé Nast
Condé Nast Data Breach
734
CRITICAL-56
CON202224323
Condé Nast notified about 1,100 WIRED subscribers of a breach involving their payment information.
They stated that an unauthorized party accessed their vendor’s systems in an attempt to acquire information.
The compromised information includes names, postal and email addresses, credit/debit card numbers, security codes, and card expiration dates.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Condé Nast ??
What was Condé Nast's A.I Rankiteo Cyber Score in September 2026 ??
What was Condé Nast's A.I Rankiteo Cyber Score in August 2026 ??
What was Condé Nast's A.I Rankiteo Cyber Score in July 2026 ??
What was Condé Nast's A.I Rankiteo Cyber Score in June 2026 ??
What was Condé Nast's A.I Rankiteo Cyber Score in May 2026 ??
What was Condé Nast's A.I Rankiteo Cyber Score in April 2026 ??
What was Condé Nast's A.I Rankiteo Cyber Score in March 2026 ??
What was Condé Nast's A.I Rankiteo Cyber Score in February 2026 ??
What was Condé Nast's A.I Rankiteo Cyber Score in January 2026 ??
What was Condé Nast's A.I Rankiteo Cyber Score in December 2025 ??
What was Condé Nast's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on Condé Nast's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Condé Nast ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Condé Nast's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?