HIGH SEVERITYAdult

MYM.fans Data Breach

MYM.fans Adult Creator Subscription Platform Breach (2025): 5.2 Million User Email Addresses Exposed

Subscription platform for creators and fan communities.

Verified by ObscureIQ Intelligence

6.0Severity
5.2MRecords
1Fields
2025Year

ObscureIQ Breach Intelligence Scores
24.0
Breach Risk Index
25
Data Value
60
Market Recency
104
days
Since Breach

Risk Interpretation

Very high sensitivity. Exposure enables extortion, harassment, fraud, and identity linkage tied to adult-adjacent or intimate creator content and subscriber relationships.

🎯 Impact & Downstream Threats

The institutional impact on MYM.fans is significant given the size of the affected user base, the sensitivity of the platform's creator-subscriber relationships, and the platform's France-based regulatory framework. The breach is subject to French data-protection authority CNIL oversight under the GDPR, which carries materially higher potential penalties than U.S. equivalents. The reputational impact is concentrated within the creator-subscription category in Europe, where MYM.fans has been a le

Primary downstream threats:
  • Targeted phishing campaigns using exposed email addresses

🔓 Threat Vectors

Phishing, credential stuffing & account takeover

📋 Breach Intelligence

EntityMYM.fans (MYM (Meet Your Model))
OrganizationPrivate Company • France / Global
Breach Date2025-01-01
DBC Added2026-01-01
Added Date2026-01-13
Records~5.2M (5,183,661 records)
Attack VectorSocial Engineering
Threat Actoresther (Leakbase distributor); original compromise: Creator.io employee social engineering
Data SubjectsUser
Breach PathwayDirect
SourceDataBreach.com / ObscureIQ
SensitivityElevated
Breach ID934.0
StatusConfirmed

📝 Executive Summary

MYM.fans, a France-based creator subscription-content platform operating as a regional OnlyFans-equivalent, suffered a data breach that surfaced publicly in November 2025 when a user named 'esther' posted the dataset on the breach-trading forum Leakbase.la. According to subsequent reporting, the leaked data may have originated from a 2021 source compromise of the MYM platform's databases, totaling approximately 1.81 gigabytes including SQL tables for distinct creator and subscriber populations. The DataBreach.com summary attributes the original compromise vector to a social-engineering attack on a Creator.io employee. MYM.fans has not publicly detailed the original incident.

The breach affected approximately 5.2 million unique user records based on records indexed by breach-tracking services, with the original Leakbase posting describing a 5.5 million-line text file. Compromised fields included email addresses and, according to forum reporting and security-research analyses of the leaked file, also included full names, physical addresses, phone numbers, and IP addresses for affected users. The dataset structure suggests it represents a complete user-database dump rather than a partial extract, including both subscriber and creator accounts.

For affected users, the practical risk profile combines identity-fraud exposure with creator-platform-specific reputational risk that varies substantially between subscriber and creator populations. For subscribers, inclusion in the dataset confirms a paid subscription relationship with a creator-monetization platform that includes adult content. Affected users who receive extortion attempts should not pay ransom demands because payment does not stop further extortion. Users should change any reused passwords on other accounts, enable two-factor authentication where available, document all extortion communications, and report extortion attempts to law enforcement. For affected creators, the disclosure carries materially greater risk because creator identification can affect employment, family relationships, immigration status, and personal safety, and because creator records may include real-name and tax-related identifiers used for monetization payouts. Affected creators may benefit from legal counsel familiar with French data-protection law and CNIL complaint processes. The continued circulation of the dataset after the Leakbase seizure means that affected users should treat the exposure as long-term rather than time-limited.

🏢 About MYM.fans

MYM.fans, also styled as 'MYM (Meet Your Model),' is a France-based subscription-content platform that operates as a creator monetization service in the OnlyFans-equivalent category. Headquartered in France, MYM.fans enables independent content creators to publish photo, video, and messaging content to paid subscribers, with the platform mediating payments, subscriptions, and direct messaging between creators and fans. While MYM.fans is not exclusively an adult-content platform, the platform's creator base includes a substantial proportion of adult-content creators, similar to OnlyFans. As an account-based creator-subscription platform, MYM.fans maintains substantial subscriber and creator account data including names, contact information, billing-related identifiers, content access history, messages between creators and fans, and monetization activity.

Platform | Creator monetization and subscription content | Social subscription platform | Global
Private CompanyFrance / Globalmym.fans

🗂 Why They Hold Your Data

Creator subscription platforms collect highly sensitive creator and subscriber identity, payment-adjacent records, content access history, messages, and monetization activity tied to paid fan relationships.

📰 Recent Developments

The MYM.fans breach was publicly disclosed in November 2025 when a forum user named 'esther' posted the dataset on the breach-trading forum Leakbase.la. DataBreach.com indexed the breach on January 12-13, 2026, and breach-tracking publications including DarkEye and InsecureWeb reported on the dataset shortly after. The Leakbase forum where the data was originally posted was subsequently seized by an international law enforcement operation led by Europol on March 3, 2026 ('Operation Leak'), which targeted 37 of the platform's most active users with arrests, house searches, and 'knock-and-talk' interviews across the U.S., Australia, Belgium, Poland, Portugal, Romania, Spain, and the U.K. The MYM.fans dataset has continued to circulate among breach-trading communities despite the Leakbase seizure. MYM.fans has not publicly detailed the original incident or the specific vulnerability that enabled the compromise.

🔍 Data Points Exposed

1 verified field types:
Email

Canonical Fields

email_address

🌐 Dark Web Verification

Confirmed
  • Dataset containing ~5.2M records identified in breach intelligence sources
  • Data indexed and searchable across breach notification platforms
  • Source: mymfans-2025

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of MYM.fans
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

Social EngineeringAdultEmail

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom