Data breach
Fling
- Records
- 40,769,518
- Breach date
- 10 March 2011Estimated
- Added
- 13 January 2025
What was exposed
6 types of data · 3 more reported · 1 puts you at serious risk
- Email addresses1
- IP addresses1
- Usernames1
- Passwords1
- Sexual preferences1
- Sexual orientation1
- Phone numbersReported, not counted
- Dates of birthReported, not counted
- GenderReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In 2011, the adult social network Fling.com was hacked, and a database containing the accounts of roughly 40.8 million users was taken. The breach is estimated to have occurred on March 10, 2011, and covers 40,769,518 records. The data did not surface publicly for years. In 2016, a seller using the handle "peace_of_mind" offered the full dump for sale on the dark web marketplace The Real Deal for less than one bitcoin, as reported by the International Business Times. An administrator connected to the Fling.com domain confirmed the data was genuine but said it came from a 2011 breach, according to reporting cited by Motherboard.
Breach Timeline
March 10, 2011: Mozilla Monitor records this date as when Fling was breached.
May 2016: The stolen database appeared for sale on the dark web market The Real Deal under the seller handle "peace_of_mind," with coverage from the International Business Times and Motherboard.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, usernames (nicknames), passwords, IP addresses, sexual fetishes, and sexual orientation.
Third-party breach records describe additional fields in the leaked data, including phone numbers, dates of birth, genders, geographic locations, and website activity. Reporting from the sale listing in 2016 indicated the passwords were stored in plain text, meaning they were not encrypted or hashed in any way.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The most immediate risk comes from the plain text passwords. Because they were never hashed, anyone holding the database can read them directly and try them against email accounts, social media, banking, and other services where the same password was reused. This technique, known as credential stuffing, remains one of the most common ways attackers break into accounts.
The personal details in this breach are also unusually sensitive. Sexual orientation, sexual fetishes, and records from an adult website can expose people to extortion, blackmail, or public embarrassment if the data is circulated. Email addresses and phone numbers are useful for targeted phishing, and attackers may craft convincing messages that reference the site to pressure victims into paying or clicking malicious links.
What Is Fling Doing in Response?
Verified public information about Fling's response is limited. When the data surfaced in 2016, an administrator connected to the domain told Motherboard the company had investigated a sample of the data and confirmed it originated from a 2011 breach, stating the site does not store credit card information. No public record of user notifications, credit monitoring offers, or other remediation steps has been confirmed as of September 25, 2026.
What Should You Do If You Were Affected?
If you had a Fling.com account, take these steps:
Change your passwords everywhere the old one was reused. Because the passwords were stored in plain text, any account sharing that password should be treated as exposed. Start with your email account, then banking and social media.
Use unique, strong passwords for each service, ideally with a password manager.
Turn on two-factor authentication where it is offered, especially for email and financial accounts.
Watch for phishing. Be skeptical of emails or texts referencing adult websites, account suspensions, or payment demands, even if they include personal details that appear legitimate.
Be alert to extortion attempts. Criminals sometimes email breach victims claiming to have compromising material and demanding payment. Do not pay; report the message instead.
Because this breach happened more than a decade ago and the data has circulated since 2016, assume the credentials are widely available and act accordingly.
In the news
- International Business Times, "Fling.com breach: Passwords and sexual preferences of 40 million users for sale on dark web"ibtimes.co.uk (opens in a new tab)
- Computerworld, "Pwned: 65 million Tumblr accounts, 40 million from Fling"computerworld.com (opens in a new tab)
- Mozilla Monitor breach details for Flingmonitor.mozilla.org (opens in a new tab)
