Data breach
Ashley Madison
- Records
- 38,373,637
- Breach date
- 19 July 2015Estimated
- Added
- 12 February 2025
What was exposed
12 types of data · 1 more reported · 2 put you at serious risk
- Email addresses1
- Ethnic groups1
- Names1
- Height1
- Password hints1
- Home addresses1
- Usernames1
- Passwords1
- Phone numbers1
- Sexual preferences1
- Sexual orientation1
- Weight1
- IP addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In July 2015, a group calling itself the Impact Team breached Ashley Madison, the dating site marketed to people seeking extramarital affairs, and stole the personal data of the site's user base. The hackers demanded the site and its sister service, Established Men, be shut down. When the company refused, the group published the stolen data online in stages. According to our investigation team, the listing contains 38,373,637 records, with the estimated breach date of July 19, 2015. No actor has formally claimed the breach in our catalog, though the Impact Team publicly took credit for the theft and leaks at the time.
July 12, 2015: Employees at Ashley Madison's parent company, Avid Life Media, found a threatening message from the Impact Team on their work computers, according to reporting by KrebsOnSecurity.
July 19, 2015: The Impact Team publicly announced the attack and threatened to release user identities within 30 days unless the sites were shut down.
July 21, 2015: The hackers released a sample of more than 2,500 customer records to prove they held the data.
August 18, 2015: The group published roughly 10 gigabytes of user data on the dark web, including member profiles and payment records.
August 20, 2015: A second dump followed, including more than 12 gigabytes of internal corporate emails.
July 2017: Avid Life Media, later renamed Ruby Corp., agreed to a reported $11.2 million settlement of lawsuits tied to the breach.
What Information Was Compromised?
Our analysis found the following data types in this breach: usernames, passwords and password hints, email addresses, phone numbers, names, home addresses, height, weight, ethnic group, sexual orientation, and sexual preferences.
Not every individual is affected by every type of data listed here.
Reporting at the time documented additional material in the leaked files. Payment records included partial credit card details, first and last names, physical addresses, and IP addresses, as covered by FedScoop. The attackers also claimed to hold private chat messages between users. The leaked database included email addresses registered to government and military domains, and records belonging to users who had paid Ashley Madison to delete their accounts, which had not actually been removed.
What Are the Potential Risks for Affected Individuals?
This breach carried unusual personal risk because the site's entire purpose was discretion. Exposed names, home addresses, and billing records could reveal affairs to spouses, employers, or communities. In the days after the leak, extortionists targeted users whose details appeared in the data, demanding Bitcoin payments and threatening exposure, as documented in contemporaneous reporting. People in countries where adultery is punishable faced elevated danger.
Conventional financial risks also apply. Email addresses paired with passwords and password hints enable credential stuffing against other accounts where the same password was reused. Partial card data and transaction records can support targeted phishing and fraud.
What Is Ashley Madison Doing in Response?
On July 20, 2015, the company posted statements saying it had secured its sites and closed unauthorized access points, was working with law enforcement, and was using the Digital Millennium Copyright Act to remove leaked user data from websites. It also waived its account deletion fee. CEO Noel Biderman stepped down in late August 2015. In July 2017, the company's parent agreed to a $11.2 million settlement covering two dozen lawsuits from the breach.
What Should You Do If You Were Affected?
Change your Ashley Madison password and any other account that used the same one.
Watch for extortion emails. Do not pay. Treat any message referencing the leak as a scam attempt and report it.
Review credit card statements from the period for unfamiliar charges, and consider a fraud alert if partial card data was exposed.
Be cautious with any email claiming to come from Ashley Madison or referencing the breach, since attackers used the leak for phishing.
In the news
- KrebsOnSecurity: Who Hacked Ashley Madison?krebsonsecurity.com (opens in a new tab)
- Wikipedia: Ashley Madison data breachen.wikipedia.org (opens in a new tab)
- Vice: Ashley Madison Hackers Speak Outvice.com (opens in a new tab)
- FedScoop: More than 15K government email domains found in Ashley Madison hack datafedscoop.com (opens in a new tab)
