Data breach
Adult FriendFinder (2016)
- Records
- 219,950,376
- Breach date
- 16 October 2016Estimated
- Added
- 1 December 2024
What was exposed
3 types of data · 1 more reported · 1 puts you at serious risk
- Email addresses1
- Usernames1
- Passwords1
- IP addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In October 2016, Friend Finder Networks, the company behind AdultFriendFinder.com, suffered one of the largest breaches on record. According to our investigation team, this listing contains 219,950,376 records tied to AdultFriendFinder, with an estimated attack date of October 16, 2016. Broader reporting on the same incident found even wider fallout: CSO Online's Salted Hash reported that six compromised databases exposed 412,214,295 accounts across Friend Finder Networks sites, including Cams.com and Penthouse.com. The breach was the second major compromise for the company in two years, following a 2015 incident that exposed about 3.5 million accounts.
October 18, 2016: A researcher using the handle 1x0123, also known as Revolver, warned Adult FriendFinder on Twitter about a local file inclusion vulnerability and posted screenshots as proof, according to CSO Online.
October 20, 2016: CSO's Salted Hash was the first to report that Friend Finder Networks had likely been compromised, potentially exposing more than 100 million accounts.
November 13, 2016: The breach notification service LeakedSource disclosed the full scale, calling it the largest hack of 2016, per CSO Online and Computerworld.
Mid-November 2016: Friend Finder Networks confirmed the incident in a press release and began directly notifying users about the stolen usernames, passwords, and email addresses, according to ZDNet.
What Information Was Compromised?
Our analysis found the following data types in this breach: nicknames, passwords, and email addresses. The catalog records show an unknown number of entries for each type, so our team could not confirm exact counts per field.
External reporting adds detail on what the leaked databases contained. ZDNet, which reviewed a portion of the data, found usernames, email addresses, last visit dates, and passwords stored in or hashed with the SHA-1 algorithm, a method considered weak by modern standards. CNBC reported the data also included last logins, IP addresses, and browser information. LeakedSource, per CSO Online, found more than 15 million accounts that users had deleted but that the company had kept on file, and identified thousands of .gov and .mil email addresses among the records. ZDNet noted this trove did not appear to contain the sexual preference data exposed in the 2015 breach.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because the data includes email addresses, passwords, and usernames, people who reused passwords across sites face the highest risk. Attackers commonly take leaked credentials and try them on banking, social media, and shopping accounts. The SHA-1 password hashing reported by ZDNet makes cracking easier than with modern algorithms, increasing that exposure.
The sensitive nature of the site raises further concerns. CSO Online and ZDNet both reported thousands of government and military email addresses in the data, and CSO Online noted the data could support blackmail or doxxing attempts. Even for people who never posted anything explicit, simply appearing in the data confirms membership on an adult service, which criminals could use for extortion.
What Is Adult FriendFinder (2016) Doing in Response?
Friend Finder Networks publicly confirmed the breach in a press release shortly after CSO's first report in October 2016, saying it had engaged external partners to support its investigation. ZDNet reported in mid-November that the company began sending direct notifications to users, citing compromised usernames, passwords, and email addresses. The company also said it had identified and rectified a vulnerability related to source code access via an injection flaw. LeakedSource, for its part, chose not to make the data searchable, a break from its usual practice.
What Should You Do If You Were Affected?
Change your password immediately, both on any Friend Finder Networks sites you used and anywhere you reused the same password. CSO Online quoted LeakedSource advising that anyone who registered on a Friend Finder site before November 2016 should assume they are affected.
Turn on two-factor authentication wherever it is offered.
Watch for phishing. Attackers may reference the site to lure you into clicking links.
Be alert to extortion attempts that cite your membership, and avoid paying or engaging.
In the news
- CSO Online: 412 million FriendFinder accounts exposed by hackerscsoonline.com (opens in a new tab)
- ZDNet: AdultFriendFinder network hack exposes secrets of 412 million userszdnet.com (opens in a new tab)
- ZDNet: AdultFriendFinder network finally comes clean to members about site hackszdnet.com (opens in a new tab)
- CNBC: Over 300 million AdultFriendFinder accounts exposed in massive breachcnbc.com (opens in a new tab)
