The encyclopedia · Software & IT · Operational decision · 2015
Ashley Madison's 2015 breach: 37M users exposed — and the fake-profile model
Hackers stole 37M user accounts from the infidelity site, revealing weak security, a fraudulent $19 delete fee, and thousands of fake female profiles.
Avid Life Media
What happened
In July 2015, a group calling itself The Impact Team hacked Ashley Madison, the dating site for married people seeking affairs, and stole the personal data of approximately 37 million users — names, addresses, emails, sexual fantasies and credit-card transaction records. The hackers accused Avid Life Media, the parent company, of fraud: charging users $19 for a promised full delete service that never actually removed their purchase history.
The breach revealed the company had built its business on deception in two ways. First, the $19 delete fee was a lie — it removed the profile but kept the billing records. Second, an analysis of the leaked data showed that of 37 million accounts, only a tiny fraction were genuine female users; the overwhelming majority were men talking to automated bots that the company had created to simulate female interest. The hackers also found 15,000 accounts registered with .mil or .gov email addresses.
The fallout was swift and severe. CEO Noel Biderman resigned a month after the breach. The U.S. Department of Justice and Federal Trade Commission fined the company $1.6 million for deceptive security practices. A class-action lawsuit later forced an $11.2 million payout to affected users. Two suicides were reported in connection with the leak, and the company faced years of brand destruction before quietly rebranding its parent as Ruby Corp.
Why it happened
- The $19 full delete feature did not remove purchase records, making the breach far more damaging than it should have been.
- Ashley Madison's user base was 90–95% male talking to automated bots — the product itself was built on deception.
- The company stored sensitive personal data with weak security for a business that depended entirely on discretion.
- Hackers published 9.7 GB of data including user identities, financial records, and employee data.
The lesson
A company whose product depends on trust cannot afford to cut corners on security — and building a fake user base to charge real customers creates a liability that a single breach can detonate.
Sources
- Ashley Madison parent company agrees to pay $1.6M to resolve civil charges — DOJ
- Online Cheating Site AshleyMadison Hacked — Krebs on Security
- What happened when hackers posted stolen Ashley Madison data — Wired
- Ashley Madison hack: 33 million users may be exposed — BBC News
spotted an error? The club wants to know.
More like this
Bombardier spent $6B building the CSeries — then gave it to Airbus for $1
Azure Front Door outage takes down M365, Xbox and Azure Portal worldwide
Cloudflare's 1.1.1.1 DNS resolver goes dark worldwide for 62 minutes
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.