Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A 2018 hack of eight adult websites exposed a file containing IP addresses, names, password hashes and 1.2 million unique email addresses. That figure was not a confirmed count of users: the site owner told Ars Technica that fewer than 107,000 people had posted across the sites during their 21 years of operation.

What happened in the 2018 breach?

On October 20, 2018, Ars Technica reported that a recently discovered hack had exposed a file of almost 98 megabytes from eight adult websites operated by Robert Angelini. Angelini confirmed the breach and took the sites offline early Saturday morning, three days after receiving notice. A message on the sites urged users to change passwords elsewhere, especially if they had reused the same password. Angelini wrote: “We will not be going back online unless this gets fixed, even if it means we close the doors forever.” Ars Technica’s October 20, 2018 report is the contemporaneous account of the incident.

Which websites were affected?

Ars named these eight sites:

  • wifelovers.com
  • asiansex4u.com
  • bbwsex4u.com
  • indiansex4u.com
  • nudeafrica.com
  • nudelatins.com
  • nudemen.com
  • wifeposter.com

The report described the sites as hosting pictures that members said showed their spouses. It said it was unclear whether all spouses had consented to the publication of intimate images.

What data was exposed?

The recovered file reportedly contained IP addresses that connected to the sites, names, password hashes and email addresses. Ars said it did not contain street addresses, partial payment-card numbers, phone numbers or transaction records—the kinds of fields included in the separate Ashley Madison breach. The report does not establish exposure of data beyond the fields it identified.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How many users were affected?

Ars reported 1.2 million unique email addresses in the file, but said it was unclear how many belonged to actual users. Angelini told the publication that fewer than 107,000 people had posted to the sites over 21 years. Those are different measures: an email-address count is not a confirmed count of people affected, and the owner’s figure refers to people who posted, not necessarily everyone whose information appeared in the file.

Have I Been Pwned’s breached-sites listing currently displays 1.3 million for Wife Lovers. That is a live listing checked on October 8, 2026, and should not be treated as equivalent to the 2018 report’s 1.2 million unique-email figure. Check Have I Been Pwned’s breached-sites listing for its current display.

Were passwords exposed, and why does Descrypt matter?

The file reportedly contained password hashes: protected representations of passwords, not passwords described by Ars as plainly readable in the file. Ars said the sites used Descrypt, a scheme created in 1979 that uses only the first eight characters of a password and has a small salt space. Password-cracking expert Jens Steube recognized the scheme quickly, according to the report. Jeremi M. Gosney, a password-security expert and Terahash CEO, told Ars: “The algorithm is quite literally ancient by modern standards, designed 40 years ago, and fully deprecated 20 years ago.”

A weak, outdated hashing scheme can make stolen password hashes less resistant to guessing. The report did not establish which individual passwords were recovered, so it would be inaccurate to say that every site password was decrypted. The separate risk is password reuse: if a person used the same password on another service, that other account could be at risk if the password was guessed or recovered.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should you do if you reused a password?

  1. Change the reused password. Update it anywhere else you used it, starting with important accounts such as email, financial services and social accounts.
  2. Give each account a unique password. A password manager can help create and keep track of distinct passwords; it cannot undo data already exposed or determine whether you were affected.
  3. Do not assume an email address proves account use. The reported 1.2 million addresses were not confirmed as 1.2 million real users.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How does this compare with the Ashley Madison breach?

The comparison is useful for understanding the reported data and scale, not for assigning a simple severity ranking. Ars contrasted this incident’s 1.2 million unique email addresses—with the true-user count unclear—with 36 million Ashley Madison account holders. It also said the Ashley Madison dump included street addresses, partial card numbers, phone numbers and transaction records that were absent from the file described in this incident. The datasets and counting methods differ, so the figures are not directly comparable measures of victims.

Have I Been Pwned operator Troy Hunt told Ars: “This incident is a huge privacy violation, and it could be devastating for people like this guy if he’s outed (or, I assume, if his wife finds out).” The sensitivity of intimate-site data means exposure can carry personal consequences beyond account security.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.