Data breach
Adult FriendFinder
- Records
- 3,600,331
- Breach date
- 21 May 2015Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 4 more reported
- Email addresses1
- IP addresses1
- UsernamesReported, not counted
- Dates of birthReported, not counted
- PostcodesReported, not counted
- Sexual orientationReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Data belonging to millions of Adult FriendFinder users leaked online in May 2015 after a hacker stole account information from the adult dating site and posted it on a darknet forum. The indexed dataset contains about 3.6 million records, and the team's estimated attack date is May 21, 2015. The breach drew immediate attention because the stolen material included not just contact details but highly personal information about users' sexual preferences and relationship status.
Breach Timeline
May 2015: Data from AdultFriendFinder members began circulating on a darknet forum. Posts attributed to a hacker using the name ROR[RG] indicated the data had been taken more than a month earlier, and the hacker reportedly sought a $100,000 ransom to keep the information hidden, according to reporting later compiled by PCMag.
May 21, 2015: Channel 4 News in the UK reported that data on as many as 3.9 million of the site's members had been leaked, including email addresses and sexual preferences. The same day, Gizmodo covered the story, noting that even users who had deleted their accounts appeared in the data.
May 22, 2015: The site's owner, FriendFinder Networks, confirmed a potential breach and said it had hired forensics firm Mandiant and was working with law enforcement, as reported by the BBC.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and IP addresses. The number of each type in the indexed records could not be determined.
Reporting from the time, including Channel 4 News as covered by the BBC, described additional fields in the stolen data: usernames, dates of birth, ZIP codes, sexual orientation, and whether a user was seeking an extramarital affair. Company statements said there was no indication that users' financial information had been leaked, and reporting indicated the leaked spreadsheets did not include credit card information.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of sexual preferences, affair-seeking indicators, and identifying details such as names, birth dates, ZIP codes, and IP addresses makes this breach unusually dangerous for those exposed. Reporting at the time, cited by PCMag and CNN, described opportunists using the leaked data for blackmail shortly after it began circulating. Users could also face phishing messages that appear convincing because they reference details the recipient believes are private, and anyone reusing an email and password combination across sites could see those credentials tried elsewhere.
The reputational risk is real as well. Europol's 2015 Internet Organised Crime Threat Assessment noted the leak left millions of customers of adult hookup sites vulnerable to extortion and social engineering.
What Is Adult FriendFinder Doing in Response?
FriendFinder Networks, the California-based company that operated the site, publicly acknowledged the potential breach days after it was reported. In a statement to the BBC, the company said it had begun working closely with law enforcement, launched an investigation with Mandiant, and would take appropriate steps to protect affected customers. It also told members to update their usernames and passwords and said it was temporarily blocking profile searches for users believed to be affected, according to an Associated Press report carried by KSL.com.
What Should You Do If You Were Affected?
If you had an Adult FriendFinder account around 2015, several steps can reduce your risk:
Change your password on any other site where you used the same one. Password reuse turns one breach into many.
Be cautious with email. Ignore messages that claim to know your membership history or sexual preferences and demand payment. Do not reply or click links.
Watch for phishing that references your email address, birth date, or location, since those details were in the stolen data.
Consider checking whether your email address appears in this or other breaches, and enable two-factor authentication where it is offered.
Because this breach combines identity data with deeply sensitive personal details, treat any contact that references it as hostile by default.
