Lovely is a financially motivated threat actor associated with the unauthorized acquisition and publication of Condé Nast subscriber data. In December 2025, the actor leaked records associated with approximately 2.3 million WIRED users and claimed access to a substantially larger dataset spanning Condé Nast brands including Vogue, The New Yorker, GQ, Glamour, Vanity Fair, and others. The exposed information included contact details and account metadata; passwords and payment-card data were not present in the initial WIRED leak. Lovely initially presented itself as a security researcher under the name Dissent Doe and claimed to have attempted vulnerability disclosure before publishing the data. Reporting associated the alleged compromise with insecure direct object reference and broken-access-control weaknesses in Condé Nast's centralized identity infrastructure, enabling unauthorized retrieval of user-profile data. Lovely subsequently offered alleged Condé Nast datasets through cybercrime forums and threatened further releases. The actor's activities create material phishing, impersonation, harassment, and data-correlation risks for affected users.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Alleged data-theft actor connected to the December 2025 WIRED leak and the claimed theft of more than 40 million Condé Nast user records. The newly advertised 32.8-million-record dataset is linked to the earlier leak, although the article notes that the current seller is not proven to be Lovely.
Leaked a dataset of ~2.3M WIRED subscriber records on underground forums and claimed (unverified) broader access affecting Condé Nast users; leak materials suggest direct access to internal account endpoints rather than scraping.
Lovely is known for leaking and selling large databases of user records from high-profile companies, most recently offering nearly 40 million user records allegedly from Condé Nast subsidiary websites, including Wired.com.
Lovely is conducting extortion and data leak operations against Conde Nast, publishing sensitive subscriber data after the company did not respond to their demands. They threaten to leak more data if their demands are not met.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.