OnlyFans users could be facing one of the platform’s biggest alleged identity-exposure incidents to date.
Hackread reported that a hacker is offering a database allegedly containing 340 million OnlyFans records on a cybercrime forum for 0.313 BTC, valued at roughly $76,000. The dataset reportedly includes information linked to both creators and subscribers, fueling concerns that anonymous accounts could potentially be connected to users’ real-world identities.
However, the massive breach claim may point to a different and increasingly common issue: recycled data compiled from previously exposed breaches.
A Closer Look Raises Questions About the Claim
The listing becomes less convincing when examined in detail. The seller, operating under the alias “Euphoric_Reply_5727,” described the database as a massive collection of OnlyFans-related records. According to the listing, the data may include:
- Usernames and names
- Email addresses and phone numbers
- Account join dates
- Follower and like counts
- Uploaded content statistics
- Account types
- Links to social media profiles
- A “card” field allegedly showing the last four digits of a payment card
However, the sample records reviewed by Hackread paint a less conclusive picture. The data appeared in a basic text format and contained incomplete entries, empty fields, and placeholders such as “None.” Some of the information also appeared to resemble publicly available profile statistics rather than data extracted directly from OnlyFans systems.
That does not make the listing entirely harmless. Several usernames and related details reportedly matched public OnlyFans profiles, including 10 UIDs associated with real usernames. Still, the linked email addresses were not independently verified, while the claimed payment-card information remains unconfirmed.
Cybernews researchers also noted that the forum post contained just 10 sample records. “Based on the sample alone, we cannot confirm the true size of the data,” the researchers said. They nevertheless warned that exposed email addresses could be useful to attackers for profiling targets or launching phishing campaigns.
Old Leaks, New Threat
The story took another turn after Hackread contacted the seller through Telegram.
The individual behind the listing reportedly denied breaching OnlyFans directly, telling Hackread that the database was created by combining existing breach and leak databases with information associated with OnlyFans users.
The seller also claimed to have used publicly available information and data from other platforms, including X, Instagram, and Spotify, to identify and match users. This suggests the alleged 340-million-record database may be less of a newly stolen OnlyFans dataset and more of a large collection assembled from previously exposed and publicly available information.
When Usernames Can Reveal Real Identities
On a platform such as OnlyFans, the biggest risk from a data exposure may not be stolen passwords—it may be the ability to identify users behind anonymous accounts.
A username can appear harmless on its own, but when combined with an email address, phone number, or linked social media profile, it may provide enough information to connect an online identity to a real person, employer, or another account they deliberately kept separate.
This type of exposure does not require a password to cause harm. Information gathered from multiple sources can potentially be used for doxxing, impersonation, account takeover attempts, extortion, or harassment, extending the impact far beyond the platform itself.
Frequently Asked Questions
Was OnlyFans actually hacked in the alleged 340 million-record leak?
Not necessarily. The seller reportedly claimed that the database was created by combining previously leaked data with information from public sources and other platforms. There is currently no confirmed evidence that OnlyFans itself was breached.
What information is reportedly included in the database?
The alleged dataset may contain usernames, names, email addresses, phone numbers, account details, social media links, and profile statistics. Claims involving payment-card information have not been independently verified.
Are all 340 million records confirmed to belong to OnlyFans users?
No. The size and origin of the database remain unverified. Researchers reportedly reviewed only a small sample of records, making it impossible to independently confirm the seller’s claim about 340 million entries.
Why can recycled breach data still be dangerous?
Old leaked information can become more useful when combined with data from other sources. Attackers may use these connections to identify individuals, conduct phishing campaigns, impersonate users, or target them with harassment and extortion.
What should OnlyFans users do to protect themselves?
Users should be cautious of unexpected emails and messages, avoid clicking suspicious links, use unique passwords, enable available security features, and review linked accounts for unnecessary personal information. If an email or phone number has appeared in previous breaches, extra caution is advisable.
Conclusion
The alleged 340 million-record OnlyFans database should be treated with caution rather than as confirmed evidence of a massive platform breach. Available samples do not establish that the data was stolen directly from OnlyFans, and the seller’s own comments suggest that much of the information may have been assembled from previous leaks and public sources.
Even so, the incident highlights a serious privacy risk. When usernames, contact details, social profiles, and old breach data are combined, seemingly separate pieces of information can potentially reveal a user’s real identity. For OnlyFans creators and subscribers, the episode is a reminder that reused personal information can remain a security risk long after the original breach occurs.
