Ashley Madison Data Breach and Extortion (Jul-Aug 2015)
Introduction
Ashley Madison was a dating website operated by Avid Life Media (ALM) specifically marketed to people seeking extramarital affairs, with the tagline ''Life is short. Have an affair.'' In July and August 2015 it became the subject of one of the most consequential data breaches of the decade: a hacker group calling itself the ''Impact Team'' exfiltrated more than 32 million user records, threatened ALM with public release, and then released the entire dataset when demands were not met.
The breach exposed the personal data of millions of people — including names, addresses, sexual preferences, and financial information — and had documented real-world consequences including extortion, suicide, divorce, and reputational destruction. It also revealed that the site had engaged in systematic deception of its male user base through fake female accounts.
The Breach and the Impact Team
The Impact Team announced the breach on 19 July 2015, posting a message threatening to release all user data unless ALM shut down both Ashley Madison and a companion site, Established Men. The group framed its demands in moral terms, calling ALM a fraud operation that profited from deception.
When ALM refused, the Impact Team released a full data dump on 18 August 2015, distributed via BitTorrent and accessible through Tor hidden services. The dataset included approximately 32 million user account records, internal ALM emails, source code, and financial records. Subsequent analysis by security researchers including Annalee Newitz at Gizmodo confirmed the dataset's authenticity.
The identities of the Impact Team members were never publicly established. No individual has been charged in connection with the breach. The attackers appear to have had inside access or prolonged network presence.
Human Consequences
The most severe consequences were documented suicides. A pastor in New Orleans, Louisiana, and a San Antonio Police Department captain both died by suicide in the weeks following the data release, with their deaths publicly connected by family members or officials to exposure in the Ashley Madison data. Security researchers and journalists documented these cases as the most concrete human costs of the breach.
Beyond documented suicides, the data release drove a wave of extortion. Individuals identified in the dataset received emails demanding Bitcoin payments in exchange for non-disclosure to spouses or employers. Divorce attorneys reported significant increases in consultations citing Ashley Madison data. Politicians, clergy, military personnel, and government employees were among those identified in the dataset, with some cases leading to career consequences or public exposure.
The Fake-Female-Profile Revelation
Security researcher Annalee Newitz''s analysis of the leaked data, published by Gizmodo in August 2015, found that the overwhelming majority of female profiles on Ashley Madison were either inactive or bot accounts created by ALM itself. The analysis found approximately 70,000 female bots and estimated that around 95% of female profiles showed no genuine human activity. The site had been selling male users the illusion of female engagement that largely did not exist.
ALM denied the findings initially. The subsequent FTC investigation confirmed that the company had operated what the FTC described as a deceptive practice — using ''engager profiles'' (company-operated bots) to generate paid messages to male users.
The FTC Settlement
The US Federal Trade Commission and thirteen state attorneys general investigated the breach and the underlying deceptive practices. In July 2016 ALM (by then renamed Ruby Corp.) agreed to a settlement: $11.2 million in civil penalties distributed among affected users, plus a $1.66 million fine paid to the FTC. The settlement required the company to implement a comprehensive data security programme.
The settlement addressed both the security failure and the deceptive ''engager profiles'' practice. It did not identify the attackers or result in criminal charges against any party.
Security Failures
Post-breach analysis identified significant security failures beyond inadequate breach prevention. Some legacy user accounts had passwords stored using MD5 hashing, a cryptographically weak method that allows rapid cracking. More recent accounts used bcrypt, a stronger method, but the legacy systems'' vulnerability meant that passwords for a significant subset of accounts were recoverable from the leaked data.
The company had also offered and charged users for a ''full delete'' service — a paid option to have all profile data removed. The leaked dataset included accounts from users who had paid for full deletion, demonstrating that the service did not function as advertised. This feature became a focal point in the FTC investigation.
Verdict
Confirmed. The data breach, its scope, its consequences — including documented suicides and the extortion wave — and the revelations about fake female profiles and deceptive practices are all documented by security researchers, law enforcement investigations, and judicial proceedings. The FTC settlement confirms the deception. The harm to real people is real and documented. This is not a conspiracy theory; it is a confirmed corporate deception and criminal data theft with documented real-world casualties.
What Would Change Our Verdict
- Identification and prosecution of the Impact Team members
- Evidence that the fake-profile proportion was materially different from what the Gizmodo/FTC analysis established
- Evidence that the company had implemented adequate security before the breach
Two Regulators, Two Settlements — Not One
Coverage of Ashley Madison's legal aftermath often blurs together two entirely separate proceedings that produced two different dollar figures. The first was the U.S. Federal Trade Commission's enforcement action, joined by thirteen states and the District of Columbia, which concluded on 14 December 2016 with a $1.6 million payment structured around a larger $8.75 million judgment against the FTC (and a matching $8.75 million against the states) that would become fully due only if the company violated the settlement's terms. The FTC complaint focused narrowly on deception: it alleged the company used fake profiles of women to convert paying male members, falsely displayed a fabricated "Trusted Security Award" trustmark, and misrepresented that its paid "Full Delete" service actually erased user data, when in fact deleted-account data remained in the leaked dump.
The second proceeding was a private consumer class action consolidated into multidistrict litigation in the U.S. District Court for the Eastern District of Missouri. That case settled separately, for $11.2 million, with preliminary court approval on 21 July 2017 — seven months after the FTC's case closed. Class members who could document financial losses tied to the breach could claim up to $3,500. The two figures are frequently merged in casual retellings into a single "$11.2 million FTC settlement," but they were different actions, brought by different parties, resolved seven months apart.
A Third Investigation: The Privacy Commissioners
Running in parallel to the American cases, the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner conducted a joint cross-border investigation, publishing their findings on 22–24 August 2016. Their report went further than the FTC's consumer-protection framing, itemizing specific technical failures: encryption keys stored as plain text, shared administrative credentials kept in a company Google Drive, and passwords stored unencrypted in emails and text files. Commissioner Daniel Therrien's office concluded that "handling huge amounts of this kind of personal information without a comprehensive information security plan is unacceptable." Avid Life Media avoided further enforcement by entering a compliance agreement with the Canadian commissioner and a court-enforceable undertaking with the Australian commissioner — the same fabricated security trustmark the FTC cited independently. The FTC and the two commissioners' offices later received a joint international award for the coordinated investigation, underscoring that regulators treated this as a landmark case in cross-border privacy enforcement, not merely a single national action.
The Hackers Who Were Never Caught
For a "confirmed" story, one central fact remains permanently unresolved: nobody has ever been publicly identified, charged, or convicted for carrying out the breach. Avid Life Media offered a reward of up to $500,000 for information leading to the Impact Team's identification; it went unclaimed. Toronto Police, who led the criminal investigation, never named a suspect.
That vacuum produced competing theories that became part of the story in their own right, and a caution against overconfident attribution. Security entrepreneur John McAfee claimed in August 2015, citing unnamed "sources within the Dark Web," that the breach was not an external hack at all but an inside job — specifically, he said "the single person is a woman, and has recently worked within Avid Life Media." McAfee offered no verifiable evidence for the claim, and it was never corroborated by law enforcement or independent security researchers. A separate, more grounded lead investigated by journalist Brian Krebs pointed to a contractor: an SEO consultant hired and then fired by Avid Life Media in 2011 after a bitter falling-out that included threatening calls and a harassment campaign against executives, with CEO Noel Biderman reportedly suspecting him immediately ("It was definitely a person here that was not an employee but certainly had touched our technical services"). That lead also collapsed on closer examination: Krebs found the man had died by suicide in March 2014, roughly sixteen months before the Impact Team's July 2015 announcement — a timeline gap even the man's own stepmother acknowledged, telling Krebs, "Considering the date of death, I'm not sure if he's your guy." As of the most recent public reporting, whether the Impact Team was an outside hacker, a disgruntled insider, or some combination remains an open question that no subsequent investigation has resolved.
The Suicide Reports: Documented, Not Definitively Proven
The breach's human toll is real, but the specific claim that circulates most widely — that the leak "caused suicides" — deserves more precision than it usually receives. On 24 August 2015, Toronto Police Staff Superintendent Bryce Evans told reporters the department was investigating two reports of suicides that family members or associates believed were connected to exposure in the leaked data. Evans was explicit that these were unconfirmed, saying "details about both cases remain sparse," and did not identify the individuals, confirm which jurisdiction the deaths occurred in, or state that a coroner had established a causal link between the data exposure and either death. No subsequent official report has converted these into confirmed, causally established cases in the public record. This does not make the underlying risk fictional — the extortion campaigns and public shaming that followed the leak were real and severe — but the "two suicides" figure that recurs across secondary coverage traces back to a single unconfirmed police briefing, not a completed investigation with documented findings on cause of death.
Reassessing the "95 Percent Bots" Number
The claim that roughly 95% of Ashley Madison's female profiles were fake is one of the story's most quoted statistics, and its origin is more tangled than the round number suggests. Gizmodo's Annalee Newitz published the first version of the analysis on 26 August 2015, under the headline "Almost None of the Women in the Ashley Madison Database Ever Used the Site." That piece itself later carried an editor's note stating the reported female-user numbers were "based in part on a misinterpretation of the data," after Newitz's original methodology inferred human activity from three database columns — bc_email_last_time, bc_chat_last_time, and email_reply_last_time — that in fact recorded when automated "engager" bot accounts, not real people, had last contacted a member. A follow-up analysis published five days later offered a revised interpretation. Separately, roughly 70,572 accounts were identified in Avid Life Media's own source code as automated engager profiles, of which 70,529 were tagged female — solid evidence that the company ran a large-scale bot operation, which the FTC's 2016 complaint later confirmed as a deceptive practice. But the specific "95% fake" framing that spread through headlines conflates several distinct measurements — bot-tagged accounts, inactive accounts, and accounts with no verified human replies — and Krebs on Security's 2022 retrospective cites a different figure again: "fewer than one percent" of female profiles used on a regular basis, alongside a finding that 84% of all Ashley Madison profiles were male. The underlying finding — that the company manufactured large numbers of fake female accounts to engage paying male users — is solid and FTC-confirmed. The precise percentage attached to it in popular retellings is not a single settled number.
How Troy Hunt Handled the Data Differently
Not every response to the leak amplified the harm. Troy Hunt, who runs the breach-notification service Have I Been Pwned, wrote on 28 July 2015 — before the Impact Team had even released the full dataset — that he intended to treat Ashley Madison differently from every prior breach he had loaded into the service. Citing warnings from fellow security researcher Per Thorsheim about the suicide risk tied to exposure of infidelity data, Hunt introduced a new "sensitive breach" category that blocked anonymous public searches; only verified account owners, or people who had already registered their own email address with the service, could learn whether an address appeared in the data. Hunt explained the decision explicitly: "I'm not prepared for HIBP to be the avenue through which a wife discovers her husband is cheating." That choice established a data-handling precedent Have I Been Pwned has applied to sensitive breaches ever since, and stands as a small case study in how researchers can respond to a mass-exposure event without either suppressing the story or maximizing collateral harm to the people named in it.
How Many Users, Really?
Even the topline number of affected accounts is not perfectly consistent across authoritative sources. Contemporaneous 2015 reporting described roughly 32 million exposed accounts; the FTC's December 2016 complaint cites 36 million consumers; class-action filings and later retrospectives frequently cite approximately 37 million members. These figures are not necessarily contradictory — Avid Life Media's user base grew between the July 2015 hack and the August 2015 data dump, and "account" is not the same thing as "unique real person," given how many records were company-generated bots, duplicates, or never-verified signups. But the spread is a useful reminder that even in a breach this thoroughly confirmed and legally adjudicated, precise headline numbers can still vary by source, snapshot date, and definition of what is being counted.
Evidence Filters16
FTC settlement confirms deceptive practices — July 2016
SupportingStrongThe $11.2M civil settlement between the FTC, thirteen state AGs, and ALM/Ruby Corp. constitutes a government finding that the company engaged in deceptive practices including operating fake female engager profiles. The settlement is a matter of public record.
Gizmodo analysis: ~95% of female profiles were bots
SupportingStrongSecurity researcher Annalee Newitz's analysis of the leaked dataset found approximately 70,000 female bot accounts created by ALM itself, estimating that around 95% of female profiles had no genuine human activity. The FTC investigation subsequently confirmed the fake-profile practice.
At least two documented suicides linked to the breach
SupportingStrongA New Orleans-area pastor and a San Antonio Police Department captain both died by suicide in the weeks after the August 2015 data release, with their deaths publicly connected to exposure in the Ashley Madison dataset. These are the most documented human casualties of the breach.
'Full delete' service confirmed fraudulent
SupportingStrongAshley Madison charged users for a 'full delete' service promising complete removal of account data. The leaked dataset included accounts from users who had paid for this service, demonstrating that the deletion did not occur as advertised. The FTC investigation confirmed this as a deceptive practice.
CEO Noel Biderman resigned 28 August 2015
SupportingAvid Life Media CEO Noel Biderman resigned on 28 August 2015, ten days after the full data dump. ALM stated his departure was by 'mutual agreement.' The timing is consistent with the immediate consequences of the breach and the incoming FTC investigation.
Legacy systems stored passwords in MD5 — crackable
SupportingStrongPost-breach security analysis found that legacy user account passwords were stored using MD5 hashing, a cryptographically weak algorithm enabling rapid cracking. More recent accounts used bcrypt. The mixed implementation meant that a significant subset of passwords was recoverable from the leaked data.
Impact Team identity never established
DebunkingNo individual has been charged in connection with the breach. The Impact Team's members remain unidentified. This is a significant limitation in the investigative record — the perpetrators are confirmed to exist by the breach itself but have not been publicly named or prosecuted.
Rebuttal
The lack of attacker identification means the motive and any insider access cannot be fully assessed. It does not change the confirmed nature of the breach, its scope, or its consequences.
Senator Joseph Carey and politicians outed in dataset
SupportingMultiple politicians and public officials were identified in the leaked data, leading to calls for transparency and some public disclosures. The identification of public figures added to the political and legal pressure that produced the FTC investigation.
Joint Canada/Australia privacy commissioner investigation independently corroborated the security failures
SupportingStrongA joint investigation by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner, published 22-24 August 2016, found encryption keys stored as plain text, shared credentials stored in a company Google Drive, and passwords stored unencrypted in emails and text files, confirming ALM's security program was inadequate independently of the FTC's parallel U.S. investigation.
FTC's December 2016 complaint provides the legal detail behind the deceptive-practice claims
SupportingStrongThe FTC and 13 states plus D.C. settled with Avid Life Media/Ruby Corp for $1.6 million on 14 December 2016, with the underlying complaint formally alleging fake female profiles, a fabricated 'Trusted Security Award' trustmark, and a non-functional paid 'Full Delete' service — giving regulatory, legally-tested confirmation to claims that had previously rested only on journalistic analysis of the leaked data.
Show 6 more evidence points
The Impact Team's identity was never established, and the most concrete suspect lead dead-ended
DebunkingStrongDespite a $500,000 reward and years of investigation, no individual has ever been publicly charged in connection with the hack. Journalist Brian Krebs's most substantive lead — a fired ALM contractor who had waged a harassment campaign against the company — collapsed when Krebs found the man had died by suicide roughly sixteen months before the breach was announced.
Rebuttal
This is a genuine limitation, not a challenge to the verdict: the breach itself, its scope, and its consequences are independently documented by regulators and litigation regardless of who carried it out. It does mean any claim asserting a specific identity or motive for the Impact Team beyond their own public statements should be treated as unproven.
The two suicide reports were described by police as unconfirmed, not causally established
DebunkingOn 24 August 2015 Toronto Police Staff Superintendent Bryce Evans told reporters the department was investigating two reports of suicides that associates believed were linked to the breach, but said 'details about both cases remain sparse' and did not confirm a causal link, identify the individuals, or cite a coroner's finding.
Rebuttal
This does not mean the harm was invented — extortion and public exposure caused by the breach are independently documented — but the specific 'two confirmed suicides' framing that recurs in secondary coverage overstates what the original police briefing actually established.
The widely-cited '95% of female profiles were bots' statistic is more contested than commonly reported
DebunkingGizmodo's original 26 August 2015 analysis by Annalee Newitz was later corrected via an editor's note after her methodology mistook timestamps generated by automated 'engager' bot accounts for evidence of human activity. A separate 2022 Krebs on Security retrospective cites a different figure ('fewer than one percent' of female profiles used regularly; 84% of all profiles male). The core finding — large-scale fake female accounts confirmed by the FTC — is solid, but the specific percentage varies by source and methodology.
Rebuttal
The FTC's own complaint independently confirms Avid Life Media operated fake 'engager' profiles as a deceptive practice, so the underlying claim (the company ran fake female accounts to engage paying men) is confirmed. Only the precise percentage figure attached to popular retellings is unsettled.
The total number of affected users is reported inconsistently across authoritative sources
DebunkingWeakContemporaneous 2015 reporting cited roughly 32 million exposed accounts; the FTC's December 2016 complaint cites 36 million; class-action litigation documents and later retrospectives commonly cite approximately 37 million. The spread likely reflects different snapshot dates and differing definitions of 'account' versus 'unique user,' rather than any single source being wrong.
Rebuttal
This is a measurement-precision caveat, not a challenge to the confirmed scope of the breach; all cited figures fall within the same order of magnitude (32-37 million) and all sources agree the breach was massive.
Impact Team's Stated Moral Motivation Was Vigilantism, Not Coordinated Institutional Action
DebunkingThe Impact Team hackers framed their action as moral punishment of Avid Life Media for operating a fraud-facilitating platform and for false 'full delete' claims. There is no credible evidence linking Impact Team to state actors, competing commercial interests, or organized crime seeking extortion leverage. The breach appears to be vigilante hacktivism — harmful and illegal, but straightforwardly motivated by the stated ideological grievance rather than a coordinated institutional conspiracy.
FTC Settlement and Business Reform Demonstrate Regulatory Accountability, Not Ongoing Cover-Up
NeutralThe FTC reached a settlement with ALM (rebranded as ruby Corp.) in 2016 requiring substantive security improvements, prohibition on fake profiles, and $1.66 million in redress. The settlement terms were publicly disclosed and subject to ongoing FTC monitoring. The company eliminated fake female 'engager' bots and implemented genuine security measures. These accountability steps — while inadequate for victims who suffered real harm — demonstrate the regulatory system responding to the breach rather than a conspiracy to suppress accountability.
Evidence Cited by Believers9
FTC settlement confirms deceptive practices — July 2016
SupportingStrongThe $11.2M civil settlement between the FTC, thirteen state AGs, and ALM/Ruby Corp. constitutes a government finding that the company engaged in deceptive practices including operating fake female engager profiles. The settlement is a matter of public record.
Gizmodo analysis: ~95% of female profiles were bots
SupportingStrongSecurity researcher Annalee Newitz's analysis of the leaked dataset found approximately 70,000 female bot accounts created by ALM itself, estimating that around 95% of female profiles had no genuine human activity. The FTC investigation subsequently confirmed the fake-profile practice.
At least two documented suicides linked to the breach
SupportingStrongA New Orleans-area pastor and a San Antonio Police Department captain both died by suicide in the weeks after the August 2015 data release, with their deaths publicly connected to exposure in the Ashley Madison dataset. These are the most documented human casualties of the breach.
'Full delete' service confirmed fraudulent
SupportingStrongAshley Madison charged users for a 'full delete' service promising complete removal of account data. The leaked dataset included accounts from users who had paid for this service, demonstrating that the deletion did not occur as advertised. The FTC investigation confirmed this as a deceptive practice.
CEO Noel Biderman resigned 28 August 2015
SupportingAvid Life Media CEO Noel Biderman resigned on 28 August 2015, ten days after the full data dump. ALM stated his departure was by 'mutual agreement.' The timing is consistent with the immediate consequences of the breach and the incoming FTC investigation.
Legacy systems stored passwords in MD5 — crackable
SupportingStrongPost-breach security analysis found that legacy user account passwords were stored using MD5 hashing, a cryptographically weak algorithm enabling rapid cracking. More recent accounts used bcrypt. The mixed implementation meant that a significant subset of passwords was recoverable from the leaked data.
Senator Joseph Carey and politicians outed in dataset
SupportingMultiple politicians and public officials were identified in the leaked data, leading to calls for transparency and some public disclosures. The identification of public figures added to the political and legal pressure that produced the FTC investigation.
Joint Canada/Australia privacy commissioner investigation independently corroborated the security failures
SupportingStrongA joint investigation by the Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner, published 22-24 August 2016, found encryption keys stored as plain text, shared credentials stored in a company Google Drive, and passwords stored unencrypted in emails and text files, confirming ALM's security program was inadequate independently of the FTC's parallel U.S. investigation.
FTC's December 2016 complaint provides the legal detail behind the deceptive-practice claims
SupportingStrongThe FTC and 13 states plus D.C. settled with Avid Life Media/Ruby Corp for $1.6 million on 14 December 2016, with the underlying complaint formally alleging fake female profiles, a fabricated 'Trusted Security Award' trustmark, and a non-functional paid 'Full Delete' service — giving regulatory, legally-tested confirmation to claims that had previously rested only on journalistic analysis of the leaked data.
Counter-Evidence6
Impact Team identity never established
DebunkingNo individual has been charged in connection with the breach. The Impact Team's members remain unidentified. This is a significant limitation in the investigative record — the perpetrators are confirmed to exist by the breach itself but have not been publicly named or prosecuted.
Rebuttal
The lack of attacker identification means the motive and any insider access cannot be fully assessed. It does not change the confirmed nature of the breach, its scope, or its consequences.
The Impact Team's identity was never established, and the most concrete suspect lead dead-ended
DebunkingStrongDespite a $500,000 reward and years of investigation, no individual has ever been publicly charged in connection with the hack. Journalist Brian Krebs's most substantive lead — a fired ALM contractor who had waged a harassment campaign against the company — collapsed when Krebs found the man had died by suicide roughly sixteen months before the breach was announced.
Rebuttal
This is a genuine limitation, not a challenge to the verdict: the breach itself, its scope, and its consequences are independently documented by regulators and litigation regardless of who carried it out. It does mean any claim asserting a specific identity or motive for the Impact Team beyond their own public statements should be treated as unproven.
The two suicide reports were described by police as unconfirmed, not causally established
DebunkingOn 24 August 2015 Toronto Police Staff Superintendent Bryce Evans told reporters the department was investigating two reports of suicides that associates believed were linked to the breach, but said 'details about both cases remain sparse' and did not confirm a causal link, identify the individuals, or cite a coroner's finding.
Rebuttal
This does not mean the harm was invented — extortion and public exposure caused by the breach are independently documented — but the specific 'two confirmed suicides' framing that recurs in secondary coverage overstates what the original police briefing actually established.
The widely-cited '95% of female profiles were bots' statistic is more contested than commonly reported
DebunkingGizmodo's original 26 August 2015 analysis by Annalee Newitz was later corrected via an editor's note after her methodology mistook timestamps generated by automated 'engager' bot accounts for evidence of human activity. A separate 2022 Krebs on Security retrospective cites a different figure ('fewer than one percent' of female profiles used regularly; 84% of all profiles male). The core finding — large-scale fake female accounts confirmed by the FTC — is solid, but the specific percentage varies by source and methodology.
Rebuttal
The FTC's own complaint independently confirms Avid Life Media operated fake 'engager' profiles as a deceptive practice, so the underlying claim (the company ran fake female accounts to engage paying men) is confirmed. Only the precise percentage figure attached to popular retellings is unsettled.
The total number of affected users is reported inconsistently across authoritative sources
DebunkingWeakContemporaneous 2015 reporting cited roughly 32 million exposed accounts; the FTC's December 2016 complaint cites 36 million; class-action litigation documents and later retrospectives commonly cite approximately 37 million. The spread likely reflects different snapshot dates and differing definitions of 'account' versus 'unique user,' rather than any single source being wrong.
Rebuttal
This is a measurement-precision caveat, not a challenge to the confirmed scope of the breach; all cited figures fall within the same order of magnitude (32-37 million) and all sources agree the breach was massive.
Impact Team's Stated Moral Motivation Was Vigilantism, Not Coordinated Institutional Action
DebunkingThe Impact Team hackers framed their action as moral punishment of Avid Life Media for operating a fraud-facilitating platform and for false 'full delete' claims. There is no credible evidence linking Impact Team to state actors, competing commercial interests, or organized crime seeking extortion leverage. The breach appears to be vigilante hacktivism — harmful and illegal, but straightforwardly motivated by the stated ideological grievance rather than a coordinated institutional conspiracy.
Neutral / Ambiguous1
FTC Settlement and Business Reform Demonstrate Regulatory Accountability, Not Ongoing Cover-Up
NeutralThe FTC reached a settlement with ALM (rebranded as ruby Corp.) in 2016 requiring substantive security improvements, prohibition on fake profiles, and $1.66 million in redress. The settlement terms were publicly disclosed and subject to ongoing FTC monitoring. The company eliminated fake female 'engager' bots and implemented genuine security measures. These accountability steps — while inadequate for victims who suffered real harm — demonstrate the regulatory system responding to the breach rather than a conspiracy to suppress accountability.
Timeline
Impact Team announces breach; demands site shutdown
The Impact Team posts a message claiming to have exfiltrated Ashley Madison's full user database and threatening to publish it unless Avid Life Media shuts down Ashley Madison and Established Men. ALM refuses and attempts to remove Impact Team materials.
Full 25GB+ dataset dumped via BitTorrent and Tor
The Impact Team releases the complete dataset — 32 million+ user records, internal emails, source code, and financial records — via BitTorrent and Tor hidden services. The data is immediately mirrored widely. Extortion emails targeting identified users begin circulating within days.
Toronto Police report two unconfirmed suicides possibly linked to the breach
Staff Superintendent Bryce Evans tells reporters the department is investigating two reports of suicides that associates believe are connected to the leaked data, but stresses 'details about both cases remain sparse' and does not confirm a causal link.
Source →CEO Noel Biderman resigns; suicides documented
CEO Noel Biderman resigns on 28 August 2015. In the same week, reports emerge of suicides connected to the breach — including a New Orleans pastor and a San Antonio police captain. Security researcher Annalee Newitz begins publishing her analysis of the bot-profile data.
Source →FTC settlement: $11.2M civil + $1.66M fine; fake profiles confirmed
The FTC and thirteen state AGs reach a settlement with ALM (by then renamed Ruby Corp.) for $11.2 million in consumer redress and a $1.66 million fine. The settlement confirms the company operated deceptive fake female 'engager' profiles and that the 'full delete' service did not work as advertised.
Source →Canadian and Australian privacy commissioners release joint investigation findings
The Privacy Commissioner of Canada and the Australian Privacy Commissioner/Acting Australian Information Commissioner publish a joint report finding ALM's security program grossly inadequate, including plaintext-stored encryption keys and a fabricated security trustmark; ALM agrees to a compliance agreement and an enforceable undertaking.
Source →FTC and 13 states finalize $1.6 million settlement with Ashley Madison operators
The Federal Trade Commission, joined by 13 states and the District of Columbia, settles deceptive-practices and data-security charges against Avid Life Media/Ruby Corp for $1.6 million, backed by a larger suspended judgment contingent on future compliance.
Source →Federal court grants preliminary approval of separate $11.2 million consumer class action settlement
A U.S. District Court judge in the Eastern District of Missouri preliminarily approves a $11.2 million settlement of consolidated consumer class-action litigation over the breach — a distinct proceeding from the FTC's earlier $1.6 million settlement.
Source →
Verdict
Impact Team breach confirmed by FTC investigation and $11.2M civil settlement (July 2016). Security researcher analysis confirmed ~95% of female profiles were bots. At least two suicides documented. CEO Noel Biderman resigned 28 August 2015. 'Full delete' service was fraudulent. Passwords stored in plaintext on legacy systems. All core claims confirmed by government investigation and judicial record.
Frequently Asked Questions
Were most Ashley Madison female profiles real?
No. Security researcher Annalee Newitz's analysis of the leaked data found approximately 70,000 female bots and estimated around 95% of female profiles had no genuine human activity. The FTC subsequently confirmed the company operated fake female 'engager' profiles to generate paid interactions with male users. The site was largely selling men the illusion of female engagement.
Did the Ashley Madison breach cause real harm?
Yes, documented. At least two suicides — a New Orleans pastor and a San Antonio police captain — were publicly connected to exposure in the dataset. A wave of extortion emails targeted identified users. Divorce attorneys reported significant spikes in consultations. The breach had concrete real-world casualties beyond data loss.
Who were the Impact Team hackers?
Unknown. No individual has been publicly identified or charged in connection with the breach. The group communicated through anonymous posts and appears to have had either inside access or prolonged network presence. Their motive, as stated, was moral: exposing ALM as a fraudulent business. Their identities remain one of the significant unresolved aspects of the case.
Were the Impact Team hackers ever identified or caught?
No. Despite a $500,000 reward and years of investigation by Toronto Police and independent researchers, no individual has ever been publicly charged in connection with the breach. Speculative theories — including John McAfee's unsubstantiated claim of a lone female insider and a separate suspect investigated by journalist Brian Krebs — have not held up; the Krebs-investigated suspect was found to have died over a year before the breach was announced.
Did the 'full delete' service actually delete data?
No. Ashley Madison charged users for a paid 'full delete' service that was supposed to permanently remove all profile data. The leaked dataset included accounts from users who had paid for this service, demonstrating it did not work as advertised. The FTC settlement confirmed this as a deceptive practice and included it as grounds for the civil penalty.
Were the reported suicides definitively caused by the Ashley Madison breach?
Not definitively. Toronto Police described two suicide reports as unconfirmed in an August 2015 briefing and did not identify the individuals or state that a coroner had established a causal link to the leaked data. The extortion and public exposure that followed the breach are independently well documented, but the specific 'confirmed suicides' framing overstates what was officially established.
Is it true that 95% of female profiles on Ashley Madison were fake?
The underlying finding — that Avid Life Media operated large numbers of automated 'engager' bot profiles impersonating women, later confirmed as a deceptive practice by the FTC — is solid. The specific '95%' figure, however, originated from a Gizmodo analysis that its own author later corrected via an editor's note after mistaking bot-activity timestamps for human activity; other analyses (including a 2022 Krebs on Security retrospective) cite different percentages, so the exact figure remains disputed even though the core practice is confirmed.
What's the difference between the $1.6 million FTC settlement and the $11.2 million settlement often cited?
They were two separate legal proceedings. The FTC, along with 13 states and D.C., settled deceptive-practices and security charges for $1.6 million on 14 December 2016. Separately, a private consumer class action consolidated in federal court in Missouri settled for $11.2 million, receiving preliminary court approval on 21 July 2017 — seven months later. Media coverage sometimes conflates the two into a single figure.
Sources
Show 12 more sources
Further Reading
- articleKrebs on Security: Ashley Madison security analysis — Brian Krebs (2015)
- articleAshley Madison: Almost None of the Women in the Site Are Real — Annalee Newitz (2015)
- articleHere's how I'm going to handle the Ashley Madison data — Troy Hunt (2015)
- paperFTC: Operators of AshleyMadison.com Settle FTC, State Charges — FTC (2016)
- articleA Retrospective on the 2015 Ashley Madison Breach — Brian Krebs (2022)
- documentaryAshley Madison: Sex, Lies & Scandal — Netflix (2024)