340 Million OnlyFans 'Mega Leak' Was Actually a Mashup of Public Profiles and Older Data Breaches, Research Finds

In the modern era of the internet, where information travels in the speed of light, the online world continued its familiar pattern of sudden alarms over personal information floating across obscure corners of the internet. 

Dark web forums and encrypted channels regularly host claims of enormous databases for sale, each one promising to expose the private lives of millions, and each one generating waves of anxiety before the details are properly examined. 

These stories travel fast because they touch on something fundamental: the uneasy sense that almost any digital footprint can eventually be collected, matched, and sold. Most of the time the reality behind the headlines turns out more complicated than the initial panic suggests, yet the claims still shape how people think about privacy and platform security.

One such episode unfolded in May when a threat actor using the handle Euphoric_Reply_5727 placed a listing on a well known cybercrime forum. 

The post described a collection of roughly 340 million records said to be tied to OnlyFans accounts, covering both content creators and ordinary subscribers. 

Image
OnlyFans leak

According to the seller the package allegedly included a range of details that would allow someone to connect online activity with real world identities. The claimed contents were presented as follows:

  • Usernames and profile names
  • Email addresses
  • Phone numbers
  • Account creation dates
  • Follower and subscriber counts along with other activity metrics
  • Classifications distinguishing creators from regular fans
  • Links to associated social media profiles
  • Limited payment related information such as the last four digits of certain cards

The asking price was set at 0.313 Bitcoin, which translated to approximately US$76,000 at the exchange rates. 

Within a short time the claim began circulating widely on social platforms and discussion boards, framed by many as evidence that the adult content site itself had suffered a major internal breach.

At first the language used in the listing gave the strong impression that the data had been taken directly from OnlyFans systems. That framing helped the story spread quickly and prompted many users to worry about the safety of their accounts. 

Journalists who covered the matter reached out to the seller through private messaging channels. 

In those conversations the individual admitted that no direct intrusion into OnlyFans infrastructure had taken place. 

The collection had instead been assembled by taking older breach data from other services, including earlier leaks involving Twitter, Instagram and Spotify, and then matching those records against publicly visible OnlyFans profiles.

The seller later admitted (to journalists) that they did not breach OnlyFans systems. 

Instead, they scraped public OnlyFans profiles and matched them against older data from previous breaches (e.g., Twitter/X, Instagram, Spotify). 

Image
OnlyFans leak

OnlyFans responded by stating that reports of a platform breach were false. 

Independent researchers who reviewed the limited sample records attached to the original listing found themselves unable to confirm either the full claimed size of the database or the overall completeness of the information it contained. 

In other words, this "leak" was essentially a compiled/mashup dataset rather than a fresh platform compromise. It was literally a large-scale data-matching and scraping.

As a result, the episode settled into the category of a sophisticated data aggregation project rather than any fresh compromise of the company’s internal systems.

Even so the compiled nature of the material did not remove every practical concern. 

When publicly visible profile details are combined with previously leaked personal information the resulting collection can still enable targeted phishing attempts, identity profiling, and efforts to connect discreet online activity with real names. 

Given the private and often sensitive character of OnlyFans content, along with the way many creators carefully manage their public presence while still relying on the same email addresses and phone numbers used elsewhere, such matching exercises carry particular weight. 

In an environment where people routinely reuse contact information across multiple platforms these kinds of reconstructions remain a genuine risk. The May listing therefore served as a clear reminder that the absence of a direct hack does not automatically mean the absence of exposure.