A hacker operating under the alias “Lovely” publicly leaked the personal data of over 2.3 million Wired.com users on a new hacking forum, Breach Stars. The exposed information includes full names, email addresses, user IDs, display names, and account activity timestamps, but does not appear to contain passwords or payment data. The hacker accused Condé Nast, Wired’s parent company, of neglecting security warnings and threatened to release additional data affecting over 40 million users if their demands are not met. The leak contains both real and system-generated email addresses, with account records dating from 2011 to 2022, indicating access to a live or archived user database.
Further reporting confirms that the data was distributed across multiple forums and that the breach involved both Wired and potentially other Condé Nast properties. The incident highlights ongoing challenges in responsible disclosure and the risks posed by threat actors seeking to pressure organizations through public data leaks. The breach has raised concerns about user privacy and the security posture of major media organizations, especially given the hacker’s claims of further unreleased data.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
The leaked WIRED dataset was later indexed by Have I Been Pwned, making the exposure searchable for affected users. HIBP described the breach as involving 2.3 million records published in December 2025, with the newest records dated to September 2025.
Subsequent reporting identified the alleged intrusion path as insecure direct object reference and broken access control flaws in Condé Nast's centralized account platform. These weaknesses reportedly allowed unauthorized viewing and modification of user profile information.
In the days after the forum post, security researchers including Hudson Rock and journalists independently confirmed that the leaked WIRED records appeared authentic. Verification included matching sample records against known account details and infostealer log data.
After being alerted through DataBreaches, Condé Nast reportedly fixed the vulnerabilities that Lovely had described. It is unclear from the reporting whether the company validated the full scope of the actor's claims or publicly acknowledged the issue.
Before the public leak, a person using the alias "Lovely" contacted DataBreaches claiming to have found serious vulnerabilities in Condé Nast's centralized identity system affecting WIRED and potentially other brands. Lovely initially presented the outreach as responsible disclosure and said the flaws could expose tens of millions of user accounts.
Alongside the WIRED leak, Lovely claimed to possess data tied to more than 40 million accounts across other Condé Nast brands such as Vogue, GQ, Vanity Fair, and The New Yorker. The actor said the wider data would be released after Condé Nast allegedly ignored repeated warnings.
On December 20, 2025, Lovely publicly posted a dataset containing about 2.3 million WIRED user records on the Breach Stars forum. The leaked data included email addresses and account metadata, with some records also containing names, phone numbers, dates of birth, and physical addresses.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
9 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcego.theregister.com
Open sourcerescana.com
Open sourcecybersecuritynews.com
Open sourcesocradar.io
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcehackread.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.