
Over 42,000 CRA Accounts Breached: What to Know
More than 42,000 Canadian taxpayer accounts have been breached since 2020. Learn more about the data breach class-action lawsuit involving CRA accounts.
May 20, 2026 - Blog
Authored By Kaitee Stuart, Packetlabs Ethical Hacker

Recent reports claiming an enormous OnlyFans data breach have reignited discussions around privacy, credential security, and the risks associated with online subscription platforms.
According to cybersecurity reporting published in May 2026, threat actors allege they are selling data tied to approximately 340 million OnlyFans records, including usernames, account activity metrics, and creator information. At the time of reporting, the claims had not been independently verified by OnlyFans.
The alleged incident has attracted attention not only because of the size of the purported leak, but because platforms involving creator identities, financial transactions, and private content carry unique privacy implications.
This article examines what is currently known about the reported OnlyFans breach, whether user passwords appear to be involved, how credential leaks differ from platform compromises, and what lessons organizations can learn from the news.
Cybersecurity researchers reported that hackers claim to possess and are attempting to sell hundreds of millions of records allegedly linked to OnlyFans users and creators. Reported data may include:
• Usernames • Email addresses (unconfirmed) • Creator metrics and engagement information • Social profile links • Account activity data
Reports suggest the leak could potentially expose information capable of identifying users or creators if verified. However, there has been important uncertainty surrounding the incident, and cybersecurity experts have cautioned against assuming that all breach claims automatically represent newly compromised platform databases.
At time of publication, public evidence confirming a direct compromise of OnlyFans infrastructure remains limited. Claims circulating on dark web forums often require extensive verification before being treated as confirmed breaches.
This is where terminology matters. A "hack" can refer to multiple scenarios:
Direct platform compromise: Threat actors gain unauthorized access to company systems.
Credential theft: Usernames and passwords are stolen from infected devices using infostealer malware.
Credential stuffing exposure: Previously leaked credentials from other services are reused against accounts.
Data aggregation: Old leaks are combined and repackaged as "new" breaches.
Recent cybersecurity reporting highlighted a separate exposure involving more than 149 million credentials gathered through infostealer malware. Researchers reported that credentials associated with many services, including OnlyFans, appeared within exposed databases. That does not necessarily indicate those companies themselves were hacked.
This distinction is important because users often assume leaked credentials automatically mean a platform failed. In many cases, compromised devices or password reuse are responsible instead.
OnlyFans has denied there was an actual breach when questioned by media, however, they have not released a detailed statement addressing the breach. Additionally, a reporter spoke to the seller and alleges they were told that the data was actually compiled from various breaches.
This data was then correlated to public OnlyFans profiles. While not enough verified information exists about the supposed breach to state that it was not the result of a successful attack against OnlyFans, given the available information it appears that the dataset was likely constructed by the seller.
Another misconception is that all user data that is available for sale came from a breach, and a new database available means a new successful breach of an organization. An organization does not need to be breached to have databases with information about their users created and circulated.
The reality is it is often possible to build profiles of which users are active on various platforms without needing to actually hack anyone. This is due to several factors, including the availability of data from successful attacks against organizations, user behaviour, and techniques for identifying active accounts with information such as a username.
While databases that are directly stolen as a result of organizational compromise generally contain accurate information when they are sold, other databases may contain a mixture of accurate information mixed in with correlated data. For example, the data released in the 2023 breach of LinkedIn was data scraped from the website and included email addresses which had been created by the malicious actors. As the email addresses were created based on scraped data, they were not entirely accurate.
As the OnlyFans data was likely created by correlating data obtained from previous breaches with enumeration of users on OnlyFans, it may not contain fully accurate information. Tools used to enumerate active usernames do create false positives, and with approximately 340 million alleged records it is implausible that the majority of these records would have been manually validated by the seller. Additionally, just because an individual uses a username on one application and it becomes associated with their email does not mean that that username on every site necessarily means that account belongs to the same person.
Unlike many mainstream services, privacy expectations surrounding OnlyFans accounts are unusually high.
Potential exposure risks may include:
• Identity disclosure • Creator anonymity loss • Financial privacy concerns • Reputation impacts • Social engineering attacks • Credential reuse attacks • Extortion attempts • Phishing campaigns
For creators, exposure could extend beyond usernames into broader online identities.
For subscribers, concerns often center around privacy and association with account activity. Because of this, even unverified breach claims receive substantial public attention.
One emerging cybersecurity trend behind many recent credential leaks is infostealer malware.
Infostealers are designed to quietly collect:
• Saved browser passwords • Session cookies • Email credentials • Cryptocurrency wallets • Authentication tokens • Login details across multiple services
Data available for sale attributed to breaches can fall into multiple categories. Not all of the data for sale is new data, or data that was directly stolen from an organization following a successful hack.
Aggregated Data: Databases that combine data from previous breaches and repackage them as new. These can contain outdated credential and financial information, as well as personal data that is still valid, such as usernames, email addresses, home addresses, and occupations.
Scraped Data: Data that was scraped from visible profiles on an application or website. While this is not a traditional breach, the data may be included by malicious actors selling data and repackaged into aggregated databases. Scraped data may also include data constructed by the databases creator using the scraped information.
New Breach Data: Unique databases of user data stolen during the breach of an organization.
Data from Infostealer Malware Logs: Contains data, including credentials, obtained from malware installed on a user’s device. These databases generally contain the most useable credential material.
The OnlyFans data for sale was likely based off of already available aggregate databases, or a newly created one using available databases from previous breaches. The usernames were then likely cross-referenced with current OnlyFans users. The accessible profiles
likely were then scraped for further data such as subscriber count which was added to the aggregated database offered for sale.
This would have been aided by user behaviour, as how users sign up for services, choose usernames, and use the platform can make it easier for someone with access to older breach data to create data profiles of users on a site that has not been exposed in a breach. This includes using the same email addresses and usernames for accounts on different platforms, and choosing to allow information such as profiles and posts to be public.
Email Address Reuse: Many people have one email address for personal use, and will use this to sign up for new services.
Username Reuse: Usernames are often personal in nature and can feel like part of your identity. Using them on different platforms also does not seem significant. You will likely hear about never reusing your password, but having a unique username on all platforms does not generally come up. Additionally, for individuals who have chosen to have more public lives, having one username is a feature that can make it easier for your followers to find you across different platforms.
Publicly Accessible Profiles and Content: Having publicly accessible profiles and content can be a source of income on many platforms. This makes leaving your profile and posts public on applications attractive to people wishing to become successful influencers and make money off of their posts. Additionally, some users may not realize they have left an account set to public or may want to leave their profile accessible for other reasons, such as social interaction with new people.
At this point, most people have had some information about them exposed as a result of a data breach. High profile breaches over the years have included Facebook, Instagram, Twitter, and LinkedIn, with the data of millions of users exposed as a result. The data exposed in these included email addresses, phone numbers, names, usernames, and locations. This information can be used as a starting point to build a larger profile about any individual affected by a past breach. The example below shows how this, along with scraping profiles of OnlyFans accounts, could have resulted in the creation of a new database exposing OnlyFans users.
First, multiple databases from previous breaches would need to have been collected in order to build a base aggregated database. This would provide different details about affected users allowing for a better profile of the user to be created by correlating the data based on a common factor in each used as the pivot. For example, in Breach A below, the email addresses, phone numbers, and a PIN number are available. Breach B includes email addresses, the username associated that email on the breached application, and the Province the user provided as their location. Breach C has emails, the username associated with the breached application, and the birthday that was provided when signing up.



As the email addresses are the common factor in all three databases, these can be used to tie the data about each user from the individual breaches together into a larger dataset. Email addresses are also likely to be unique to an individual making it more likely that the correlated data from the three databases is actually associated with the same individual.
The combined data now has two unique usernames that the user has used previously. Usernames can often be used to identify whether or not that username has been used on a platform.
After enumerating active usernames, these can be added into the new database as the OnlyFans username. Publicly available data on OnlyFans could then be retrieved for each active user. This can include the number of videos and images posted, as well as the subscriber count. This data is added to the new database, tying each of the identified users on OnlyFans and their publicly accessible activity to personally identifying information, such as email addresses and birthdays.
In the above example aggregated data, only the usernames and subscriber count are directly associated with OnlyFans. The rest of the data has been correlated together only based on the email address in common in the records. Information such as locations, PIN numbers, and phone numbers may no longer be accurate depending on the age and accuracy of the original records.
However, it still provides enough information about active users on OnlyFans to potentially identify an individual using it. This can pose some concerns for users who may be exposed in the available database as it could lead to reputational impact as well as make them targets for social engineering attacks and potentially extortion attempts.
Although headlines focus on OnlyFans, the broader cybersecurity lessons apply across industries.
Organizations should consider:
Passwords alone provide limited protection.
Organizations increasingly rely on:
• Multi-factor authentication (MFA) • Risk-based authentication • Session monitoring • Device trust validation
Additional identity controls help reduce damage when credentials are stolen elsewhere.
Large breach claims often appear on dark web marketplaces before companies become aware of exposure.
Organizations benefit from:
• Threat intelligence monitoring • Credential exposure monitoring • Dark web surveillance • Incident response planning
Early detection can reduce downstream risk.
Historically, organizations prioritized protecting payment information.
Modern incidents demonstrate that identity data behavioral data and account associations equal meaningful privacy exposure.
Sensitive contextual information can sometimes create more harm than credit card theft.
Employees, contractors, and users often introduce risk through:
• Infected devices • Weak passwords • Browser-stored credentials • Reused authentication details
Security strategies increasingly require endpoint visibility in addition to perimeter defenses.
Individuals worried about recent breach reports should consider practical precautions:
Change passwords if reused elsewhere
Enable multi-factor authentication whenever available
Use unique passwords for every service
Monitor email accounts for phishing attempts
Review login activity where supported
Check whether credentials have appeared in known exposure databases
Avoid clicking unsolicited messages claiming account compromise
Users frequently underestimate how often credential reuse creates cascading exposure across multiple services.
Cybersecurity reporting often begins with claims posted on underground forums.
Not all claims prove accurate.
Some incidents involve:
• Recycled datasets • Old breaches relabeled as new • Inflated record counts • Aggregated credential collections
Security investigations may take weeks or months before confirming scope and authenticity. Similar situations have occurred previously where initially alarming claims were later determined to involve historical data.
This is why responsible breach analysis distinguishes between alleged exposure and confirmed compromise.
The recent OnlyFans breach news highlights a larger cybersecurity reality: users and organizations operate within an ecosystem where credentials, personal information, and behavioral data have become valuable targets.
Whether the reported 340 million-record leak proves fully accurate, the incident underscores ongoing concerns around identity protection, credential theft, infostealer malware, and privacy risk.
For organizations, the lesson is clear: cybersecurity resilience requires more than perimeter defenses. Continuous monitoring, stronger authentication controls, penetration testing, and proactive threat detection are increasingly essential.
For users, unique passwords, multi-factor authentication, and awareness of credential exposure remain some of the most effective defenses against an evolving threat landscape.