Hacker Selling 340 Million OnlyFans User Records Built From Old Breaches

2026-05-25T08:51:43Z17181225543d5d1d662fb124ceeb34bef8d795eb63984b7e2917c623b636e03d
android-malwareapi-keysasusbotnetci-workflowcloud-credentialscredential-theftdata-breachdata-exposurefileless-malwaregcpgitHubgoogle-cloudlaw-enforcementmalicious-extensionmfa-bypassmshtaphishingphishing-as-a-serviceransomware-support-servicesrouter-exploitsms-fraudsupply-chain-attackvisual-studio-codevpn-seizure

What happened

Multiple high-impact threats reported: a hacker is selling a 340 million OnlyFans user dataset allegedly built by correlating old breaches and public profiles; VulnCheck attributes the RondoDox botnet to exploitation of a critical 2018 ASUS router authentication bypass to hijack over one million devices; the FBI warns of Kali365, a phishing-as-a-service that lets attackers bypass MFA and take over Microsoft 365 accounts; SafeDep uncovered the Megalodon supply-chain attack that injected malicious CI workflows into 5,561 GitHub repositories to harvest cloud credentials; a study found deleted Git

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
17181225543d5d1d662fb124ceeb34bef8d795eb63984b7e2917c623b636e03d
Enrichment time
2026-05-25T08:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.