CSIDB logo
Incident

FriendFinder Networks

Incident posture

Attack window
May 2015
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-15 13:09

Linked entities

Victim
FriendFinder Networks
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A major breach at FriendFinder Networks exposed sensitive personal data of nearly four million users, including sexual preferences, email addresses, usernames, birth dates, postcodes, and IP addresses. Compromised information from both active and deleted accounts was leaked on a dark web forum, leading to immediate spam campaigns targeting victims and raising concerns about potential blackmail due to the highly personal nature of the data. The company initiated an investigation with law enforcement and third-party forensic experts, pledging to address the issue and protect affected customers.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In May 2015, hackers compromised personal data from nearly four million users of Adult FriendFinder, a dating platform operated by FriendFinder Networks Inc. The attackers posted the stolen information on a dark web forum inaccessible through conventional search engines. The leaked dataset included explicit details such as users’ sexual orientations, preferences for extramarital relationships, email addresses, usernames, dates of birth, postal codes, and device IP addresses. Channel 4 News first reported the breach, noting that even users who had requested account deletions were affected. Within hours of the forum posting, other hackers announced intentions to weaponize the data through spam campaigns targeting the exposed individuals. One confirmed victim, Shaun Harper, reported receiving virus-laden emails shortly after his information appeared in the leak, despite having previously deleted his account.

The breach impacted Adult FriendFinder’s global user base of 63 million, including over seven million UK members. Cybersecurity experts warned that the granularity of the stolen data—combining identifiers like names, birthdates, and locations—created significant risks beyond spam, enabling targeted blackmail attempts against specific individuals. Charlie McMurdie, a PwC cybercrime specialist and former head of London’s electronic crime unit, emphasized this escalation potential. FriendFinder Networks acknowledged the incident publicly, confirming collaboration with law enforcement and the engagement of third-party forensic experts to investigate the source and scope of the compromise. The company issued a statement affirming its awareness of the severity of the situation and pledging to implement protective measures for affected customers, though no specific remediation steps were disclosed in the initial response.

Sources

Sources available to members: 1 source.

CSIDB