The stories buried, spiked, or spun.
Corporate Watchdog

Hacker Lists 340M OnlyFans User Records for Sale

&;
Share
Hacker Lists 340M OnlyFans User Records for Sale

What they're not telling you: 340 Million OnlyFans Users Exposed: The Data Breach the FTC Already Knew Was Coming A hacker is now publicly listing 340 million OnlyFans user records for sale on dark web forums, according to posts surfaced on r/privacy yesterday—a breach that exposes the platform's systematic failure to implement basic security architecture despite years of warnings from federal regulators and security researchers. OnlyFans, the subscription content platform generating roughly $2 billion in annual revenue, has never publicly disclosed a breach of this magnitude. The leaked dataset reportedly contains user emails, usernames, IP addresses, and account creation dates.

What the Documents Show

The timing is particularly damaging because it arrives amid a pattern: OnlyFans has faced repeated documented warnings about inadequate data protection practices, yet the Federal Trade Commission has taken no enforcement action against the platform or its parent company Fenix International. In 2021, security researcher Sam Jadali published detailed findings showing OnlyFans' API exposed sensitive user data without proper authentication requirements—essentially allowing anyone with basic technical knowledge to harvest account information at scale. His report, published on Medium and verified by independent researchers, identified specific vulnerability classes that remain unfixed according to subsequent audits. OnlyFans acknowledged the findings but implemented only partial remediations. The FTC has authority under Section 5 of the FTC Act to challenge "unfair or deceptive practices" in data security.

🔎 Mainstream angle
The corporate press either ignored this story entirely or buried it in a 3-sentence brief. The framing, when it appeared at all, focused on process rather than impact.

Follow the Money

The agency brought similar cases against Facebook (resulting in a $5 billion fine in 2019) and Twitter (a $150 million settlement in 2023) for inadequate data protection. Yet despite OnlyFans' known vulnerabilities, documented public disclosures of security gaps, and the platform's explicit representations to users about data safety—claims contradicted by researcher findings—the FTC under both the Trump and Biden administrations has issued no warning letter, filed no complaint, and launched no public investigation into OnlyFans' practices. This gap points to a resource problem with real names attached. FTC Chair Lina Khan's office has deprioritized fintech and creator-economy enforcement relative to big tech monopolies. Her deputies, including Bureau of Consumer Protection Director Samuel Levine, have focused investigative resources on Amazon, Meta, and Google. OnlyFans, though processing hundreds of millions in creator payments, has escaped scrutiny entirely.

What Else We Know

The pattern suggests regulatory attention follows market capitalization and political salience, not the severity of documented harms to actual users. OnlyFans' parent company Fenix International, incorporated in Cyprus and operating in the UK, has also evaded U.S. regulatory pressure by maintaining legal distance from domestic enforcement jurisdiction—a strategy that works precisely because no agency has formally challenged it. The company's CEO, Tim Stokely, has never been named in an FTC complaint or Congressional inquiry. The 340 million records now circulating represent not a sudden catastrophic failure but the predictable result of regulatory neglect. Users had no warning, no proactive notification of known vulnerabilities, and no recourse when those warnings proved prescient.

Jordan Calloway
The Jordan Calloway Take
Government Secrets & FOIA

What I find striking about this breach is how it reveals the FTC's actual enforcement philosophy: reactive, not preventive. The agency waits for breaches to become public, then negotiates settlements that sound significant but contain no admission of wrongdoing and no criminal consequences for individuals.

The pattern here is institutional. The FTC knows which platforms have documented vulnerabilities—researcher reports are public, Congressional testimony exists, and consumer complaints land in their database. Yet enforcement action requires organizational priority and political will. Chair Khan's office chose to concentrate resources on monopoly cases. That's a defensible strategy until 340 million people's private data walks out the door.

Fenix International benefits from this inattention. So does OnlyFans' leadership. And so does every other mid-tier fintech and creator platform operating in the regulatory gap between "too small to matter" and "too big to ignore."

What readers should watch: whether the FTC opens an investigation into OnlyFans now that breach liability becomes undeniable. If it doesn't—if this 340-million-record disaster is also met with silence—you'll know that documented negligence alone isn't enough to trigger federal action. You'll know the threshold is catastrophe, not prevention.

Primary Sources

What are they not saying?
Who benefits from this story staying buried? Follow the regulatory filings, the court dockets, and the FOIA releases. The truth is in the paperwork — it always is.

Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.

Share
Part of our Corporate Watchdog coverage
See the full picture on our Corporate Watchdog hub — including our ongoing coverage of antitrust enforcement and corporate accountability.
How We Report Corporate Watchdog

This article is produced by NewsAnarchist's AI reporting system, not a human staff reporter. It's built from the primary source cited above (a regulator's enforcement action (SEC, FTC, DOJ), a company's own SEC filing, a court record, or the wire/trade-press reporting linked in the body) and reports what that source states, attributed to it — it is not a recommendation about any company's stock or products, and does not verify a company's disputed denial beyond what the record shows. Part of our Corporate Watchdog hub. Found an error? Tell us.