Hacker Lists 340M OnlyFans User Records for Sale
What they're not telling you: 340 Million OnlyFans Users Exposed: The Data Breach the FTC Already Knew Was Coming A hacker is now publicly listing 340 million OnlyFans user records for sale on dark web forums, according to posts surfaced on r/privacy yesterday—a breach that exposes the platform's systematic failure to implement basic security architecture despite years of warnings from federal regulators and security researchers. OnlyFans, the subscription content platform generating roughly $2 billion in annual revenue, has never publicly disclosed a breach of this magnitude. The leaked dataset reportedly contains user emails, usernames, IP addresses, and account creation dates.
What the Documents Show
The timing is particularly damaging because it arrives amid a pattern: OnlyFans has faced repeated documented warnings about inadequate data protection practices, yet the Federal Trade Commission has taken no enforcement action against the platform or its parent company Fenix International. In 2021, security researcher Sam Jadali published detailed findings showing OnlyFans' API exposed sensitive user data without proper authentication requirements—essentially allowing anyone with basic technical knowledge to harvest account information at scale. His report, published on Medium and verified by independent researchers, identified specific vulnerability classes that remain unfixed according to subsequent audits. OnlyFans acknowledged the findings but implemented only partial remediations. The FTC has authority under Section 5 of the FTC Act to challenge "unfair or deceptive practices" in data security.
Follow the Money
The agency brought similar cases against Facebook (resulting in a $5 billion fine in 2019) and Twitter (a $150 million settlement in 2023) for inadequate data protection. Yet despite OnlyFans' known vulnerabilities, documented public disclosures of security gaps, and the platform's explicit representations to users about data safety—claims contradicted by researcher findings—the FTC under both the Trump and Biden administrations has issued no warning letter, filed no complaint, and launched no public investigation into OnlyFans' practices. This gap points to a resource problem with real names attached. FTC Chair Lina Khan's office has deprioritized fintech and creator-economy enforcement relative to big tech monopolies. Her deputies, including Bureau of Consumer Protection Director Samuel Levine, have focused investigative resources on Amazon, Meta, and Google. OnlyFans, though processing hundreds of millions in creator payments, has escaped scrutiny entirely.
What Else We Know
The pattern suggests regulatory attention follows market capitalization and political salience, not the severity of documented harms to actual users. OnlyFans' parent company Fenix International, incorporated in Cyprus and operating in the UK, has also evaded U.S. regulatory pressure by maintaining legal distance from domestic enforcement jurisdiction—a strategy that works precisely because no agency has formally challenged it. The company's CEO, Tim Stokely, has never been named in an FTC complaint or Congressional inquiry. The 340 million records now circulating represent not a sudden catastrophic failure but the predictable result of regulatory neglect. Users had no warning, no proactive notification of known vulnerabilities, and no recourse when those warnings proved prescient.
Primary Sources
- Source: r/privacy
- Category: Government Secrets
- Cross-reference independently — don't take our word for it.
Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.