Data breach
Eroticy
- Records
- 1,597,446
- Breach date
- 1 June 2015Estimated
- Added
- 12 February 2025
What was exposed
2 types of data · 6 more reported · 1 puts you at serious risk
- Email addresses1,309,091
- Passwords1
- NamesReported, not counted
- UsernamesReported, not counted
- Home addressesReported, not counted
- Phone numbersReported, not counted
- IP addressesReported, not counted
- Purchase historyReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
The investigation team has indexed a breach affecting Eroticy, an adult website that let users arrange discreet encounters. The team estimates the breach dates to around June 1, 2015, and covers 1,597,446 records, including 1,309,091 email addresses. The data surfaced publicly years after the intrusion: Mozilla Monitor lists the breach in its database as of January 10, 2017, and notes it was added only after discovery and verification. No hacker or group has publicly claimed responsibility, and the exact method of the attack remains unclear.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
June 1, 2015: Mozilla Monitor records this as the date Eroticy was breached.
January 10, 2017: Mozilla Monitor lists the breach as added to its database, roughly 19 months after the estimated attack date.
What Information Was Compromised?
Our analysis found the following data types in this breach: passwords and email addresses, with 1,309,091 email addresses counted in the indexed records.
The breach listing on Mozilla Monitor describes additional data types in the compromised records: names, usernames, physical addresses, phone numbers, IP addresses, payment histories, and website activity.
Not every individual is affected by every type of data listed here.
The password count in the indexed records is not specified, but the breach services that track this dataset report passwords among the exposed fields. Because this is an adult website, much of the exposed information is inherently sensitive: real names, home addresses, and payment histories tied to accounts users may have expected to remain private.
What Are the Potential Risks for Affected Individuals?
The exposure of passwords and email addresses creates a direct risk of account takeovers. People who reused the same password on other services may find those accounts targeted through credential stuffing, where attackers try leaked email and password pairs across many websites.
The personal details in the records, including names, addresses, and phone numbers, can also support targeted phishing. Messages that quote accurate personal information are more convincing and more likely to trick recipients into clicking links or handing over further details.
Because the breach involves an adult website, there is an additional risk of harassment or extortion. Attackers sometimes email people from breaches like this one and threaten to expose their membership or browsing history unless they pay. These threats are common scams, but they can feel very personal, and accurate data in the leak makes them more credible.
What Should You Do If You Were Affected?
If you had an account on Eroticy, take these steps:
Change your Eroticy password immediately, if you still use the account, and choose a unique password you have not used anywhere else.
Change the password on any other account where you reused the same one. Password reuse turns one breach into many.
Turn on two-factor authentication wherever it is offered, especially on your primary email account.
Be cautious with unexpected emails or texts that reference the site, your membership, or your personal details. Do not click links or pay extortion demands; report them instead.
Consider a password manager so every account can have its own strong password.
