Skip to main content
Breach Signal

Breach report

Social Media

Friend Finder Networks (Adult FriendFinder)

Adult FriendFinder hit with one of the biggest data breaches ever, report says

Hackers took more than 412 million accounts from adult dating company Friend Finder Networks, including Adult FriendFinder and Penthouse.com, with passwords stored in plaintext or weak hashes and millions of supposedly deleted accounts.

Reported by The Washington Post

Records exposed

412M

412 million accounts

Scale vs. largest on file

When
2016
How they got in
Local file inclusion vulnerability
Sector
Social Media

In November 2016, breach search site LeakedSource reported that Friend Finder Networks, the company behind the adult dating and webcam site Adult FriendFinder, had been hacked the previous month. The stolen data covered more than 412 million accounts spread across six databases, making it the largest breach reported that year and one of the largest ever at the time.

The haul included roughly 340 million accounts from Adult FriendFinder, alongside records from Cams.com, Penthouse.com, Stripshow.com, iCams.com and another property. The data stretched back some two decades and included usernames, email addresses, membership dates and last login dates. Passwords were either stored in plaintext or hashed with SHA-1, and LeakedSource said it was able to recover nearly all of them. The dump also contained more than 15 million accounts that users had deleted, suggesting the company retained data long after members asked to leave.

The attack was linked to a local file inclusion vulnerability, a flaw that lets an attacker trick a web application into exposing files from its server. A security researcher using the name Revolver had publicly flagged such a weakness on Adult FriendFinder in October 2016. Friend Finder Networks initially said it was investigating reports of security vulnerabilities and later acknowledged it had identified and fixed a flaw, without confirming the full scope of the breach.

Because of the nature of the sites, the exposure carried unusual personal risk. Thousands of records were tied to government and military email addresses, raising concerns about blackmail and extortion. The breach came only 18 months after a separate 2015 incident at Adult FriendFinder that exposed data on about 3.5 million users, including sexual preferences, which had already drawn scrutiny of the company's security.

The case is often cited alongside Ashley Madison as evidence that adult and dating services hold some of the most sensitive data on the internet but have sometimes applied weak protections. It reinforced several enduring lessons: never store passwords in plaintext, honor deletion requests by actually removing data, and minimize retention of old records. For users, it showed that deleting an account does not necessarily mean the data is gone.

More from the wire

More in Social Media.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.