The 2015 Ashley Madison data breach was a major cybersecurity incident in which a hacker group known as "The Impact Team" breached the user databases of Ashley Madison, a commercial website billing itself as an enabler of extramarital affairs. Discovered in July 2015, the hackers stole internal company data and personal information—including names, email addresses, sexual fantasies, and financial records—belonging to approximately 32 million users.
In July 2015, the hackers demanded that Ashley Madison's parent company, Avid Life Media (ALM, now Ruby Life Inc.), shut down Ashley Madison and a sister site, Established Men. When ALM refused and attempted to proceed with a planned $200 million initial public offering (IPO) in London, The Impact Team released more than 25 gigabytes of sensitive data onto the dark web in August 2015. The breach led to widespread public shaming, secondary extortion scams targeting exposed users, high-profile resignations, and several reported suicides. It remains one of the most infamous examples of hacktivism and corporate data negligence in internet history.
Background and extortion demand
Ashley Madison operated under the infamous slogan, "Life is short. Have an affair." However, the site was long criticized for its questionable and predatory business practices. Notably, "The Impact Team" justified their attack by citing Ashley Madison's "Full Delete" feature. The site charged users a $19 fee to completely erase their profiles. This feature alone brought in $1.7 million in revenue in 2014. However, the hackers discovered that the company routinely retained users' payment details, real names, and billing addresses even after the fee was paid.
On July 12, 2015, ALM employees logging into their computers were greeted with the AC/DC song "Thunderstruck" and a threatening manifesto from The Impact Team. The hackers gave the company 30 days to permanently take Ashley Madison and Established Men offline. They claimed they were punishing the company for fraudulent practices, specifically identifying the use of thousands of fake female bot accounts—internally known as "Angels"—designed to trick male users into purchasing expensive messaging credits.
The data dumps
When Avid Life Media failed to comply with the demands and instead attempted to downplay the breach, The Impact Team followed through on their threat. On August 18, 2015, a 9.7-gigabyte compressed archive (expanding to much larger uncompressed) containing the personal details of roughly 32 million users was uploaded to the dark web via an Onion routing hidden service. Researchers noted that while passwords were mathematically hashed using the bcrypt algorithm, an older, weaker MD5 hash was left in the codebase for millions of accounts, making them easy to crack.
Two days later, on August 20, a second, larger data dump was released. This 20-gigabyte release contained a file named noel.biderman.mail.7z, comprising the personal emails of CEO Noel Biderman, as well as the source code for the company's websites and internal corporate documents. The data definitively proved that out of the millions of female profiles on the site, only a few thousand were active human women; the vast majority were the aforementioned "Angel" bots.
Human cost and secondary extortion
The fallout from the data dump was immediate and devastating. Security researchers and opportunistic developers quickly built searchable public databases that allowed anyone to check if an email address was in the leak. This led to mass public shaming. High-profile individuals exposed in the breach included reality TV star Josh Duggar, Christian vlogger Sam Rader, and numerous politicians, executives, and users of official .gov and .mil email addresses.
Hacktivism and Moral Vigilantism
The Impact Team positioned themselves as moral vigilantes, targeting Ashley Madison not just for poor security, but for what they deemed an immoral business model fueled by fraudulent "fembots."
The Dark Web Data Dump
Over 25GB of SQL databases, internal emails, and user financial transactions were dumped on Tor networks, making it easily accessible to opportunistic cybercriminals.
Furthermore, cybercriminals aggressively exploited the leak by initiating widespread extortion campaigns. Hackers emailed victims threatening to send proof of their Ashley Madison accounts to their spouses, employers, or social media networks unless a ransom was paid, typically demanding around 1.05 Bitcoin (equivalent to ~$225 USD at the time). Tragically, police in Toronto reported that the breach was linked to at least two unconfirmed suicides, and several other suicides globally were directly tied to the extortion attempts and ensuing public humiliation. In response, ALM offered a $500,000 CAD bounty for information leading to the hackers' arrest.
Corporate fallout and resignations
Noel Biderman
Former CEO of Avid Life Media, who stepped down shortly after the devastating 2015 leak of internal company emails.
The release of CEO Noel Biderman's emails was particularly damning for the company's public image and legal standing. The internal communications revealed that Biderman himself had engaged in multiple extramarital affairs, blatantly contradicting his frequent public statements claiming he was faithful to his wife. One internal email thread even showed Biderman pitching a highly controversial, misogynistic app concept called "What's Your Wife Worth."
Most importantly, the emails proved the executive team was fully aware of, and actively directed, the creation of the fake bot accounts being used to defraud male customers. Facing intense public backlash, plummeting company valuation, canceled IPO plans, and undeniable proof of corporate fraud, Noel Biderman resigned as CEO of Avid Life Media on August 28, 2015.
Legacy and legal settlements
The Ashley Madison hack fundamentally altered the public's understanding of internet privacy, corporate data liability, and the absolute permanence of digital footprints. It demonstrated that relying on a company's promise to delete data is often misplaced trust.
In July 2017, Ruby Corp (the rebranded name of Avid Life Media) agreed to pay $11.2 million to settle a sprawling class-action lawsuit brought on behalf of the 37 million users whose data was compromised. Additionally, in late 2016, the U.S. Federal Trade Commission (FTC) and several state attorneys general reached a settlement with the company resulting in an additional $1.6 million penalty for their lax data security and deceptive "bot" practices. Despite the massive scandal and total collapse of its original reputation, Ashley Madison rebranded itself, shifted its marketing strategy towards "open relationships" and polyamory, and remarkably continues to operate today. To this day, the true identities of the individuals behind "The Impact Team" remain a mystery.