Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
OnlyFans

OnlyFans Vendor Cyber Rating & Cyber Score

onlyfans.com

OnlyFans empowers creators to own their full potential. OnlyFans is a place for creators from all genres and is committed to building the most inclusive and safest social media platform in the world. OnlyFans is a space for creators to express themselves freely, monetize content, and develop authentic connections with their fans. We continue to put power into the hands of creators by developing unparalleled opportunities for our community.


OnlyFans A.I CyberSecurity Scoring

OnlyFans
Company Information
Website:http://www.onlyfans.com
Employees number:5,901
Number of followers:81,445
NAICS:71
Industry Type:Entertainment Providers
Homepage:onlyfans.com
OnlyFans Risk Score (AI oriented)
Between 0 and 549
logo
OnlyFansEntertainment Providers
Updated:
27/05/2026
277/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
OnlyFans Global Score (TPRM)
xxxx
logo
OnlyFansEntertainment Providers
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

OnlyFans
OnlyFansCritical
Current Score
277C (CRITICAL)
01000
5 incidents
-136.25 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
285Before Incident
MAY 2026
389Before Incident
Breach
25 May 2026OnlyFans
OnlyFans: 340M OnlyFans Database Listed for Sale

OnlyFans User Data Allegedly Compiled from Old Breaches, Offered for Sale

277After Incident
CRITICAL-112
ONL1779791617
OnlyFans User Data Allegedly Compiled from Old Breaches, Offered for Sale A hacker operating under the alias Euphoric_Reply_5727 is advertising a claimed 340 million-record OnlyFans database on a cybercrime forum for 0.313 BTC (approximately $76,000). The dataset reportedly includes usernames, real names, email addresses, phone numbers, join dates, follower counts, linked social profiles, and partial payment card details raising concerns about the exposure of users’ real identities. However, investigations by Hackread and Cybernews suggest the data may not be the result of a direct breach. The seller later admitted to compiling the information from existing leaks and public sources, cross-referencing OnlyFans profiles with data from platforms like X (formerly Twitter), Instagram, and Spotify. While some records matched public profiles, the sample provided just 10 entries contained inconsistencies, including blank fields and unverified details. Despite the questionable origins, the compilation poses risks. Even if the data is recycled, exposed emails and linked accounts could enable phishing, doxxing, or targeted harassment. The incident underscores the broader threat of identity linkage, where seemingly harmless usernames can be traced back to real-world identities, potentially leading to extortion or account takeovers without requiring a password leak.
INCIDENT DETAILS -
TYPE
Data Compilation
MOTIVATION
Financial gain
IMPACT
Data Compromised: Usernames, real names, email addresses, phone numbers, join dates, follower counts, linked social profiles, partial payment card detailsBrand Reputation Impact: Potential reputational damage due to exposure of user identitiesIdentity Theft Risk: HighPayment Information Risk: Partial payment card details exposed
DATA BREACH
UsernamesReal namesEmail addressesPhone numbersJoin datesFollower countsLinked social profilesPartial payment card detailsNumber Of Records Exposed: 340 million claimedSensitivity Of Data: HighPersonally Identifiable Information: Yes
APRIL 2026
383Before Incident
MARCH 2026
376Before Incident
FEBRUARY 2026
365Before Incident
JANUARY 2026
565Before Incident
Breach
23 Jan 2026OnlyFans
Yahoo, Facebook, TikTok, Netflix, Microsoft Outlook, OnlyFans, Binance and Canadian service provider: Massive Data Breach Exposes 149 Million User Passwords For Gmail, Facebook, & More

Massive Credential Breach Exposes 149 Million Logins in Unsecured Database

359After Incident
CRITICAL-206
YAHFACTIKNETMICONLBINCAN1769189638
Massive Credential Breach Exposes 149 Million Logins in Unsecured Database A security researcher recently uncovered a staggering data exposure involving 149 million usernames and passwords left unprotected on the internet. The database, hosted by a Canadian service provider, was freely accessible via a standard web browser, allowing anyone to search and extract sensitive login details without authentication. The breach remained active for about a month, with new credentials continuously added before the hosting provider took it offline following notification. The compromised data spanned a wide range of platforms, including: - Email services: 48 million Gmail, 4 million Yahoo, and 1.5 million Microsoft Outlook accounts - Social media: 17 million Facebook, 780,000 TikTok, and 100,000 OnlyFans logins - Streaming & entertainment: 3.4 million Netflix subscriptions - Financial services: 420,000 Binance cryptocurrency accounts, along with banking and credit card details - Government & education: 1.4 million .edu domain credentials and other official systems Investigators traced the breach to infostealing malware, which infects devices through phishing, malicious downloads, or compromised websites. The malware logs keystrokes and captures login credentials, funneling them into centralized databases like the one discovered. Each entry included unique identifiers, suggesting the database was designed for large-scale criminal operations, such as account takeovers or ransomware attacks. The implications of this breach are severe, with risks ranging from identity theft and financial fraud to potential espionage via compromised government and academic accounts. The incident reflects a broader trend of unsecured databases and the growing accessibility of cybercrime tools renting infrastructure for such operations can cost as little as $200–$300 per month, enabling even low-skilled threat actors to amass vast troves of data. While no immediate exploits have been confirmed, the exposure underscores persistent vulnerabilities in data security practices. Similar breaches have repeatedly demonstrated how quickly stolen credentials circulate on underground forums, prolonging the threat long after the initial leak. The full impact of this incident may unfold over time as attackers exploit the exposed information.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain, Account Takeovers, Ransomware Attacks
IMPACT
Data Compromised: 149 million usernames and passwordsSystems Affected: Email services, social media, streaming, financial services, government/education accountsBrand Reputation Impact: HighIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
UsernamesPasswordsBanking/Credit Card DetailsNumber Of Records Exposed: 149 millionSensitivity Of Data: HighPersonally Identifiable Information: Yes
Breach
23 Jan 2026OnlyFans
Netflix, Facebook, TikTok, Binance, OnlyFans, Microsoft Outlook, Apple iCloud, Consumer Banks and Government Systems: 149 million login details leaked via unsecured database

Massive Exposed Database Containing 149 Million Credentials Discovered Online

359After Incident
CRITICAL-206
NETFACTIKBINONLMICAPPCONGOV1769182444
Massive Exposed Database Containing 149 Million Credentials Discovered Online Security researcher Jeremiah Fowler uncovered a publicly accessible database containing 149 million usernames and passwords, including credentials for major platforms and sensitive systems. The unsecured collection, which was freely accessible via a web browser, included 48 million Gmail accounts, 17 million Facebook logins, 420,000 Binance credentials, 3.4 million Netflix accounts, 780,000 TikTok logins, and 100,000 OnlyFans accounts. Additionally, it held 1.5 million Microsoft Outlook, 900,000 Apple iCloud, and 1.4 million .edu credentials, along with login details for government systems and consumer bank accounts. Fowler reported the database to the Canadian hosting provider, which took it offline after nearly a month for violating its terms of service. During this period, the database continued to grow, suggesting ongoing data collection. Fowler suspects the credentials were harvested via infostealing malware, which logs keystrokes when victims enter login details on compromised sites. The discovery highlights the thriving infostealer market, where stolen credentials are sold for as little as $10 per log on the dark web. The simplicity of such malware makes it a popular tool for cybercriminals, enabling large-scale credential theft with minimal effort. The incident underscores the risks of unsecured databases and the widespread impact of infostealer-driven breaches.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain
IMPACT
Data Compromised: 149 million credentialsBrand Reputation Impact: HighIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
UsernamesPasswordsNumber Of Records Exposed: 149 millionSensitivity Of Data: HighPersonally Identifiable Information: Yes
DECEMBER 2025
667Before Incident
Breach
16 Dec 2025OnlyFans
Mixpanel and Adult Platform: Pornhub Premium Hack: User Activity Data Leaked

Adult Platform Premium Service Data Breach and Extortion Threat

560After Incident
CRITICAL-107
MIXONL1766496633
Cybersecurity Breach Exposes Sensitive Data of Adult Platform’s Premium Users A cyberattack targeting an adult platform’s Premium service has sparked extortion threats and heightened privacy concerns after the hacking group ShinyHunters claimed to have stolen over 201 million records of user activity logs. The company confirmed the breach stemmed from a third-party analytics vendor, Mixpanel, but clarified that only Premium users were affected and that no passwords or payment details were exposed. The stolen data reportedly includes email addresses, search queries, video titles, timestamps, and IP-based geolocation—information that, while not directly financial, could enable de-anonymization, targeted phishing, or blackmail. ShinyHunters has allegedly used the dataset to pressure the company, mirroring tactics seen in past breaches involving sensitive content, such as the 2015 Ashley Madison hack. The incident underscores the risks of supply chain vulnerabilities, where even secure primary systems can be compromised through third-party integrations. While Mixpanel denied its systems were breached, the event highlights the dangers of unchecked telemetry data collection, which can inadvertently expose sensitive behavioral logs. Privacy advocates warn that such datasets can reveal personal preferences, relationships, or routines, making them prime targets for extortion. Regulatory scrutiny is likely, with potential investigations under laws like GDPR or California’s privacy statutes. The company has pledged to audit its analytics pipeline, reduce data retention, and implement stronger safeguards for personally identifiable information. For affected users, the breach serves as a reminder of the persistent risks tied to behavioral tracking—even when financial data remains secure.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion, data monetization on dark web
IMPACT
Data Compromised: 201,211,943 records of user activity logsSystems Affected: Third-party analytics vendor (Mixpanel)Operational Impact: Potential reputational damage, regulatory scrutinyBrand Reputation Impact: High (sensitive behavioral data exposure)Legal Liabilities: Potential under GDPR, CCPA, or other privacy lawsIdentity Theft Risk: Moderate (de-anonymization risk via behavioral data)Payment Information Risk: None (no payment data exposed)
DATA BREACH
User activity logsBehavioral telemetryNumber Of Records Exposed: 201,211,943Sensitivity Of Data: High (intimate behavioral data)Data Exfiltration: Yes (alleged by ShinyHunters)Email addressesGeographic information (IP-based)Timestamps of activity
NOVEMBER 2025
666Before Incident
OCTOBER 2025
664Before Incident
SEPTEMBER 2025
662Before Incident
AUGUST 2025
777Before Incident
Breach
01 Aug 2025OnlyFans
OnlyFans: Hackers claim to hold 340 million OnlyFans user records

OnlyFans Data Leak Exposes 340 Million Records

657After Incident
CRITICAL-120
ONL1779863122
OnlyFans Data Leak Exposes 340 Million Records, Though Claims Remain Unverified Hackers have posted on a data leak forum claiming to possess 340 million records allegedly sourced from OnlyFans, the subscription-based adult content platform with over 4.5 million creators and 380 million users. The leaked data reportedly includes usernames, email addresses, account activity metrics (such as follower counts, likes, and media uploads), payment card details, and linked profiles. The threat actors deny breaching OnlyFans directly, instead asserting that the database was compiled from prior leaks, public sources, and other security incidents. Cybersecurity researchers at Cybernews analyzed a sample of the data and found it contained only a dozen records including user IDs, names, emails, and registration details dating back to August 2023. This suggests the information is outdated rather than the result of a new breach. OnlyFans has denied any recent security compromise, stating that the claims are false. However, experts warn that even outdated exposed data could be weaponized for phishing attacks, with cybercriminals potentially cross-referencing emails with other breaches to build detailed profiles of affected individuals. The full scope and authenticity of the leak remain unverified.
INCIDENT DETAILS -
TYPE
Data Leak
IMPACT
Data Compromised: Usernames, email addresses, account activity metrics, payment card details, linked profilesBrand Reputation Impact: Potential reputational damage due to unverified claimsIdentity Theft Risk: High (phishing attacks, cross-referencing with other breaches)Payment Information Risk: High (payment card details exposed)
DATA BREACH
UsernamesEmail addressesAccount activity metricsPayment card detailsLinked profilesNumber Of Records Exposed: 340 million (unverified)Sensitivity Of Data: High (personally identifiable and financial information)Personally Identifiable Information: Yes (names, emails, user IDs, registration details)
JULY 2025
777Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for OnlyFans ?
?
What was OnlyFans's A.I Rankiteo Cyber Score in May 2026 ?
?
What was OnlyFans's A.I Rankiteo Cyber Score in April 2026 ?
?
What was OnlyFans's A.I Rankiteo Cyber Score in March 2026 ?
?
What was OnlyFans's A.I Rankiteo Cyber Score in February 2026 ?
?
What was OnlyFans's A.I Rankiteo Cyber Score in January 2026 ?
?
What was OnlyFans's A.I Rankiteo Cyber Score in December 2025 ?
?
What was OnlyFans's A.I Rankiteo Cyber Score in November 2025 ?
?
What was OnlyFans's A.I Rankiteo Cyber Score in October 2025 ?
?
What was OnlyFans's A.I Rankiteo Cyber Score in September 2025 ?
?
What was OnlyFans's A.I Rankiteo Cyber Score in August 2025 ?
?
What was OnlyFans's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on OnlyFans's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with OnlyFans ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view OnlyFans's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?