Breach report
Social MediaAshley Madison (Avid Life Media)
Online Cheating Site AshleyMadison Hacked
The Impact Team hacked affair-dating site Ashley Madison in 2015 and dumped data on tens of millions of users after the company refused to shut down, triggering extortion waves, lawsuits and the CEO's exit.
Reported by Krebs on Security
Records exposed
37M
About 37 million users (claimed)
Scale vs. largest on file
- When
- 2015
- How they got in
- Network intrusion and data theft by hacktivist group
- Sector
- Social Media
On July 19, 2015, security journalist Brian Krebs reported that a group calling itself The Impact Team had breached Avid Life Media, the Toronto-based owner of Ashley Madison, a dating site marketed to married people seeking affairs. The hackers claimed to hold data on roughly 37 million users and posted samples along with internal company documents. Their demand was blunt: take Ashley Madison and sister site Established Men offline permanently, or they would publish everything.
The group said it was motivated partly by the company's paid-delete service, which charged users about $19 to erase their profiles. The hackers alleged that purchase records, including real names and addresses, were never actually removed. Avid Life Media confirmed the intrusion, and chief executive Noel Biderman suggested someone with past access to the network may have been involved. How the attackers got in was never fully disclosed.
When the company kept operating, The Impact Team followed through. In August 2015, it released gigabytes of data, including account details, partial card data and transaction histories, followed by a second dump containing Biderman's email. Journalists and researchers found the data largely genuine. They also found that a very small share of profiles belonged to women who actively used the site, and later reporting showed the company had used automated bots to engage male users.
The human fallout was severe. Extortionists sent threatening emails to people found in the data, demanding bitcoin to stay silent. Some users were publicly outed, and police in Toronto linked at least two suicides to the leak. Biderman stepped down in late August 2015. In 2016, Canadian and Australian privacy commissioners found serious security failings, and the company settled with the US Federal Trade Commission and a group of state attorneys general, paying $1.6 million. A 2017 US class action settlement added $11.2 million. The company later rebranded as Ruby Life.
Ashley Madison remains a defining case of how a breach can cause harm far beyond financial loss. It showed that the sensitivity of data, not just its volume, determines the damage, and it exposed the gap between a company's privacy promises and its actual practices. The lessons on data deletion, minimization and honest marketing still resonate across the dating industry.