Back to the archive

The encyclopedia · Software & IT · Operational decision · 2015

Ashley Madison's 2015 breach: 37M users exposed — and the fake-profile model

Hackers stole 37M user accounts from the infidelity site, revealing weak security, a fraudulent $19 delete fee, and thousands of fake female profiles.

Avid Life Media

What happened

In July 2015, a group calling itself The Impact Team hacked Ashley Madison, the dating site for married people seeking affairs, and stole the personal data of approximately 37 million users — names, addresses, emails, sexual fantasies and credit-card transaction records. The hackers accused Avid Life Media, the parent company, of fraud: charging users $19 for a promised full delete service that never actually removed their purchase history.

The breach revealed the company had built its business on deception in two ways. First, the $19 delete fee was a lie — it removed the profile but kept the billing records. Second, an analysis of the leaked data showed that of 37 million accounts, only a tiny fraction were genuine female users; the overwhelming majority were men talking to automated bots that the company had created to simulate female interest. The hackers also found 15,000 accounts registered with .mil or .gov email addresses.

The fallout was swift and severe. CEO Noel Biderman resigned a month after the breach. The U.S. Department of Justice and Federal Trade Commission fined the company $1.6 million for deceptive security practices. A class-action lawsuit later forced an $11.2 million payout to affected users. Two suicides were reported in connection with the leak, and the company faced years of brand destruction before quietly rebranding its parent as Ruby Corp.

Why it happened

  • The $19 full delete feature did not remove purchase records, making the breach far more damaging than it should have been.
  • Ashley Madison's user base was 90–95% male talking to automated bots — the product itself was built on deception.
  • The company stored sensitive personal data with weak security for a business that depended entirely on discretion.
  • Hackers published 9.7 GB of data including user identities, financial records, and employee data.
What it cost$1.6M DOJ fine; $11.2M settlement; CEO resigned; brand deadcatastrophic

The lesson

A company whose product depends on trust cannot afford to cut corners on security — and building a fake user base to charge real customers creates a liability that a single breach can detonate.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →