惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

N
News and Events Feed by Topic
Malwarebytes
Malwarebytes
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
C
Cybersecurity and Infrastructure Security Agency CISA
F
Future of Privacy Forum
C
Cisco Blogs
T
The Exploit Database - CXSecurity.com
A
Arctic Wolf
S
Securelist
K
Kaspersky official blog
S
Schneier on Security
T
ThreatConnect
T
Tenable Blog
Spread Privacy
Spread Privacy
T
True Tiger Recordings
AWS News Blog
AWS News Blog
F
Fox-IT International blog
量子位
T
Threatpost
V
Vulnerabilities – Threatpost
C
CERT Recently Published Vulnerability Notes
Cisco Talos Blog
Cisco Talos Blog
GbyAI
GbyAI
宝玉的分享
宝玉的分享
腾讯CDC
G
Google Developers Blog
aimingoo的专栏
aimingoo的专栏
Cyberwarzone
Cyberwarzone
有赞技术团队
有赞技术团队
S
SegmentFault 最新的问题
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
Visual Studio Blog
U
Unit 42
雷峰网
雷峰网
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Simon Willison's Weblog
Simon Willison's Weblog
O
OpenAI News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The GitHub Blog
The GitHub Blog
The Register - Security
The Register - Security
MyScale Blog
MyScale Blog
小众软件
小众软件
A
About on SuperTechFans
Last Week in AI
Last Week in AI
Y
Y Combinator Blog
博客园 - 三生石上(FineUI控件)
美团技术团队
Google Online Security Blog
Google Online Security Blog
P
Proofpoint News Feed
MongoDB | Blog
MongoDB | Blog

Hackread – Cybersecurity News, Data Breaches, AI and More

RondoDox Botnet Exploits Critical 2018 Vulnerability to Hijack ASUS Routers FBI Warns of Kali365 Phishing Service Targeting Microsoft 365 Account 5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours Deleted Google API Keys Remain Active up to 23 Minutes, Study Finds Europol Seizes First VPN Used by Ransomware Gangs, Arrests Administrator Android Malware Spotted Subscribing Victims to Paid Services Without Consent Microsoft’s Retired IE Tool MSHTA Now Being Used in Fileless Malware Attacks Understanding Trend Structure: Higher Highs and Lower Lows Explained GitHub Breach: TeamPCP Steals 3,800 Repositories via VS Code Extension Verizon DBIR: AI Helped Hackers Exploit Vulnerabilities in 31% of Recent Breaches Fake Word Phishing Reveals Enterprise Blind Spot in Trusted Remote Access Tools Banana RAT Malware in Fake Invoices Hits Customers at 16 Brazilian Banks AI Agent Security: Automating Workflow Without Creating Prompt Injection or Data Leak Risks How Parts Inventory Management Software Fixes Inventory Challenges Pwn2Own Berlin 2026 Closes With $1.3 Million in Zero-Day Payouts Criminal IP Returns to Infosecurity Europe 2026 with Advanced AI-Driven TI & ASM Two-Thirds of Nonhuman Accounts Are Unseen and Unmanaged, According to Orchid Security's Identity Gap Hosting Service Standards That Define High-Performing Agencies Hackers Actively Exploit ‘Nginx Rift’ Vulnerability Affecting NGINX, F5 Products 10 Top OSINT Tools Every Investigator Should Know in 2026 New Reaper Malware Uses Fake Microsoft Domain to Steal macOS Passwords 10 Tips for Phrasing Employee Feedback in Reviews Government Backed Hackers Abuse Cloudflare in Malaysian Espionage Campaign Continuous Detection, Continuous Response: Mate Security Redefines the Modern SOC The Gentlemen Ransomware Gang Hit by Internal Breach, Operations Exposed Closing the Gap: The Regulatory and Structural Maturation of Digital Assets Scammers Send Physical Phishing Letters to Steal Ledger Wallet Seed Phrases Grafana Says It Rejected Ransom Demand After Source Code Theft AI Voice Cloning: The Technology Behind It, Who's Building It, and Where It's Headed Critical ‘Claw Chain’ Vulnerabilities Put Thousands of OpenClaw AI Servers at Risk The Next Cybersecurity Challenge May Be Verifying AI Agents Hackers Use PyInstaller and AMSI Patching to Deliver XWorm RAT v7.4 CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions Fake Job Interview Apps Drop JobStealer Malware on Windows and macOS How Fintech APIs Are Modernizing Business Cash Flow Management FamousSparrow Targeted Oil and Gas Industry via MS Exchange Server Exploit China-Linked Twill Typhoon Uses Fake Apple and Yahoo Sites for Espionage TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack Instructure Reaches Deal with ShinyHunters to Prevent Canvas Data Leak TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages Slovakian Admin of Dark Web Kingdom Market Jailed for 16 Years in US Why Canadian Telecom Providers Are Prime Targets for Cyberattacks Canvas Hackers ShinyHunters Say Their Official Domain Was Suspended Fake Claude Code Installer Targets Developers With Browser Credential Stealer Pwn2Own Berlin 2026 Hits Capacity as Rejected Hackers Release 0-Days Top Video Downloaders in 2026: Why Wondershare UniConverter Remains a Strong Choice Operation HumanitarianBait Uses Fake Aid Documents to Deploy Python Spyware Google Says Hackers Used AI to Develop a Zero-Day Exploit Romanian Man Faces Up to 30 Years in US Prison Over Vishing Scams 9-Year-Old Dirty Frag Vulnerability Enables Root Access on Linux Systems Lyrie.ai Joins First Batch of Anthropic’s Cyber Verification Program Hackers Exploit Vercel GenAI to Mass-Produce Convincing Phishing Sites Two US Men Sentenced for Helping North Korean Hackers Infiltrate US Firms Hackers Trick DigiCert Into Issuing Certificates Used to Sign Malware Hackers Hijack JDownloader Site to Deliver Malware Through Installers Fake macOS Troubleshooting Sites Used to Steal iCloud Data in ClickFix Scam ClaudeBleed Vulnerability Lets Hackers Hijack Claude Chrome Extension to Steal Data ShinyHunters Defaces Canvas LMS Portal, Hundreds of Universities Affected Hackers Use Fake Claude AI Site to Infect Users With New Beagle Malware Researcher Shows Edge Browser Stores Saved Passwords in Plaintext Google Chrome Accused of Silently Installing 4GB AI Model on User Devices Why Outdated Maintenance Software Is a Growing Ransomware Risk Scammers Use Hidden Text to Bypass AI Email Filters in Phishing Scams Best OSINT Tools for Investigations and Threat Intelligence in 2026 Google Fixes CVSS 10 Gemini CLI Vulnerability Enabling GitHub Issue-Based RCE ShinyHunters’ Instructure Canvas LMS and Vimeo Breaches Impact Millions of Users Building Strategic Advantage With Integrated Planning The "Juice" Factor: Designing Game Feel Application Security Strategies Are Changing as AI-generated Code Floods the SDLC Massive “Low and Slow” DDoS Attack Hits Platform With 2.45 Billion in 5 Hours LuxSci Launches Enterprise-Grade HIPAA-Compliant Email Security for Mid-Sized Healthcare Organizations Anti-ICE Site GTFO ICE Accused of Exposing Data of 17,000+ Activists FEMITBOT Network Abuses Telegram Mini Apps for Crypto Scams and Android Malware Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities Cyber-Secure Philanthropy: Tech Infrastructure for Global Donations 7 Key Features That Make Secure Browsers Safer Paying Ransom Won’t Help as VECT 2.0 Ransomware Destroys Data Irreversibly Google AppSheet Exploited in 30,000-User Facebook Phishing Operation 2 US Cybersecurity Experts Jailed for Aiding ALPHV (BlackCat) Ransomware 45,000 Attacks, 5,300+ Backdoors Tied to China-Linked Cybercrime Operation Hackers Use Jenkins Access to Deploy DDoS Botnet Against Gaming Servers Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations Critical cPanel Vulnerability Lets Attackers Bypass Login, Gain Root Access Best Diagram Software in 2026, Why EdrawMax Works for Everyday Use Private Chats, Photos of Celebs Exposed in Suspected Stalkerware Leak Misconfigured Server Run by Hackers Leaks 345,000 Stolen Credit Cards Managed vs Self-Managed Cloud Hosting: Choosing the Best Option for Your Business 9-Year-Old Linux Kernel Vulnerability “Copy Fail” Enables Full Root Access Cursor AI Agent Wipes PocketOS Database and Backups in 9 Seconds New AI-Powered Bluekit Phishing Kit Targets Major Platforms with MFA Bypass Attacks Polymarket Rejects Data Breach Claims as Hacker Alleges 300K Records Stolen Brinker Introduces a Novel Approach to Deepfake Detection US-Estonian Suspect Arrested Over Alleged Scattered Spider Cyberattacks Cursor AI IDE Vulnerability Allows Code Execution Via Hidden Git Hooks Top AI-Powered Vendor Risk Management Platforms for SaaS Companies in 2026 New DHL Phishing Scam Uses 11-Step Attack Chain to Steal Passwords Decoding Q1 2026's $152.9 Billion Crypto Custody ConcentrationDecoding Q1 2026's $152.9 Billion Pack2TheRoot: 12-Year-Old Linux PackageKit Flaw Enables Full Compromise Stablecoins: Always-On Money Needs Always-On Controls New Linux FIRESTARTER Backdoor Targets Cisco Firepower Devices
Hacker Selling 340 Million OnlyFans User Records Built From Old Breaches
Waqas · 2026-05-25 · via Hackread – Cybersecurity News, Data Breaches, AI and More

A threat actor is advertising what they describe as a massive database containing information linked to hundreds of millions of OnlyFans users, including creators and subscribers. However, conversations with the seller and a review of sample data suggest that the collection did not result from a direct breach or scraping of OnlyFans systems.

The listing appeared earlier this week on a well-known cybercrime forum, where a user operating under the alias “Euphoric_Reply_5727” offered what they described as “340 Million User Records” linked to OnlyFans users. The seller priced the database at 0.313 BTC, roughly $76,000 at the time of writing.

According to the forum post, the collection allegedly contains data pulled from “internal OnlyFans databases,” including personal information, account activity metrics, linked social profiles, and payment-related details.

Threat Actor Denies Hacking OnlyFans

The seller advertised the database as containing usernames, names, email addresses, phone numbers, follower counts, likes, uploaded content statistics, account types, and linked social media profiles. The claims initially gave the impression of a direct platform breach or scraping incident.

However, the story changed after Hackread.com contacted the threat actor directly on Telegram. In private messages, the seller clarified they did not hack or breach OnlyFans. Instead, they claimed the database was built using information collected from previous data leaks and public sources, including breached records from platforms such as Twitter, Instagram, and Spotify.

“We didn’t breach or hack OnlyFans,” the seller said in a message shared with Hackread.com. “We used existing breaches and leaks databases and matched with users of the OnlyFans platform.”

Hacker Selling 340 Million OnlyFans User Records Built From Old Breaches
Screenshot shared by the threat actor shows 35GB of data (Image credit: Hackread.com)

Sample Data Offers More Context

After speaking with the seller, Hackread.com reviewed sample records shared from the database. The data appears to be organized as a flat text-based collection containing fields such as usernames, email addresses, phone numbers, join dates, follower counts, likes, uploaded content statistics, linked social profiles, and account types.

Some entries also included a field labelled “card,” which the seller claimed referred to the last four digits of a payment card linked to an account.

A closer look at the samples revealed incomplete records, placeholder values such as “None,” and publicly visible profile metrics. The formatting also differed from how modern consumer platforms typically store production database records internally.

Hacker Selling 340 Million OnlyFans User Records Built From Old Breaches
Threat actor’s post (Image credit: Hackread.com)

Hackread.com independently verified that several usernames and linked details in the sample data matched real OnlyFans accounts. For example, 10 UIDs listed in the shared records matched usernames linked to publicly accessible OnlyFans profiles.

However, attempts to validate associated email addresses did not produce warnings indicating the emails were already registered on the platform, leaving further verification to OnlyFans itself.

Payment Card Claims Remain Unverified

One detail that remains unclear is the seller’s claim regarding payment card data. The listing described the “card” field as containing the last four digits of a payment card associated with an account. Hackread.com could not independently confirm whether that information is authentic, recycled from older leaks, or included to increase the perceived value of the dataset.

Nevertheless, the collection still presents privacy and security concerns. Correlating usernames, emails, phone numbers, and social media accounts can expose creators and subscribers to phishing campaigns, blackmail attempts, stalking, impersonation, and targeted harassment.

The incident also shows a growing underground trend where threat actors combine old breach data with publicly accessible information to build searchable identity databases. In many cases, the value comes less from stolen passwords and more from linking online personas to real-world identities.

At the time of writing, the data was still available for sale. Hackread.com has reached out to OnlyFans for comment.