Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In August 2015, hackers published sensitive Ashley Madison user information, including profile, account-security and billing data associated with more than 36 million users, according to the U.S. Federal Trade Commission (FTC). The breach followed earlier intrusions into the company’s network and a public threat to expose the data unless two sites operated by Avid Life Media (ALM) shut down.

What happened in the Ashley Madison hack?

A group calling itself The Impact Team said it had hacked ALM, the Canadian company operating Ashley Madison and Established Men. On July 15, 2015, the group announced the hack and threatened to publish information unless both sites were shut down, according to a joint investigation by Canada’s and Australia’s privacy commissioners.

The FTC identifies July 12, 2015, as the date of a major breach of the company network. It also says intruders had accessed company networks several times between November 2014 and June 2015 without the operators discovering the intrusions. These dates describe different events: earlier intrusions, a major network breach, the group’s public announcement and, later, publication.

When were the Ashley Madison records published?

The joint Canadian-Australian investigation dates publication of information the group claimed to have stolen to August 18 and 20, 2015. The FTC describes the publication more broadly as occurring in August 2015. Its settlement announcement says hackers published sensitive profile, account-security and billing information for more than 36 million AshleyMadison.com users.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How many accounts and people were affected?

The FTC reported that the published information concerned more than 36 million Ashley Madison users. The joint privacy investigation described approximately 36 million user accounts. Those official figures refer to users or accounts; they do not establish an equal number of unique people.

The sources also describe the service’s reach in different terms. The FTC said AshleyMadison.com had members in over 46 countries, while the joint investigation described ALM as having users in over 50 countries, including Australia. These are each source’s own descriptions of its relevant population.

What information was exposed?

The FTC characterized the published data as sensitive profile, account-security and billing information. It noted that Ashley Madison had assured users that information such as date of birth, relationship status and sexual preferences would be private and secure. The privacy commissioners likewise considered the incident in the context of a service marketed to people seeking discreet affairs.

Exposure of account data does not by itself establish how any particular person used the service or what they did in their personal life. The official sources summarized here do not establish whether a specific reader’s information appeared in the stolen material. This article does not link to or reproduce the records.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Did Ashley Madison’s $19 Full Delete remove personal information?

No, not consistently, according to the FTC’s 2016 consumer guidance. Ashley Madison charged $19 for a “Full Delete” that purported to remove information from its network, including a person’s name, relationship status, sexual preferences, desired encounters, photographs and financial information. The FTC reported that information could remain for up to 12 months after a Full Delete request and that profiles were sometimes not removed at all. Those findings supported the FTC’s allegations that the company’s deletion representations were misleading.

What did regulators allege, and what did the settlement require?

FTC and state allegations

The FTC alleged that the operators misrepresented their security practices and a “Trusted Security Award,” and that their information-security practices were deficient. The complaint cited the lack of a written information-security policy, unreasonable access controls, inadequate employee security training, insufficient knowledge of service-provider safeguards and a lack of measures to monitor system security. These were allegations in the FTC complaint; they should not be confused with the terms the operators later agreed to.

Privacy commissioners’ findings

The Canadian privacy commissioner’s public summary of the joint investigation with the Office of the Australian Information Commissioner said safeguards and policies were inadequate and described a security trustmark as fabricated. The August 23, 2016, release characterized the fictitious trustmark as deceptive. Read the commissioner’s summary.

Settlement outcome

On December 14, 2016, the FTC announced that the operators had agreed to a comprehensive data-security program, including third-party assessments, and total payments of $1.6 million to settle FTC and state actions. The FTC case record names Ruby Corp. (formerly Avid Life Media Inc.), Ruby Life Inc. (also doing business as AshleyMadison.com) and ADL Media Inc. as defendants; it lists federal action 1:16-cv-02438. Read the FTC settlement announcement or view the FTC case record.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is not established about the breach?

The official sources cited here do not identify the individuals behind The Impact Team or establish the precise technical route used to access ALM’s systems. They also do not support conclusions about whether a particular person’s information was included in the stolen data. The joint privacy commissioners’ investigation provides the group’s announcement and publication dates, the company context and findings about safeguards, but it does not resolve those questions.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.