CSIDB logo
Incident

Shadi.com

Incident posture

Attack window
Jul 2016
Location
India
Status
Historical
CIA posture
Available to members
Updated
2025-12-10 00:00

Linked entities

Victim
Shadi.com
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Muslim matrimonial website experienced a significant data breach, compromising nearly 2 million user records including email addresses, names, dates of birth, and private messages. The stolen data contained approximately 150,000 exposed credentials and over 500,000 user communications, with passwords stored in unencrypted plaintext format on the primary platform while an affiliated dating site used weakly hashed MD5 encryption. The breach led to underground trading of user profiles alongside unrelated incidents affecting other niche dating platforms, though the full scope of unauthorized access remained unclear.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In July 2016, user account data from matrimonial websites Shadi.com and MuslimMatch.com was traded on digital underground platforms following security breaches. MuslimMatch.com experienced a confirmed hack on July 1, 2016, resulting in the public leakage of nearly all its user data. On July 10, 2016, Leaked Source obtained stolen datasets from both platforms, containing approximately 2 million combined user records. The compromised information included email addresses, names, dates of birth, and passwords. For Shadi.com, all passwords were stored in unencrypted plaintext format, while MuslimMatch.com used MD5 hashing for password storage—an algorithm known for cryptographic weaknesses that enable relatively easy decryption. Approximately 150,000 user credentials and profiles from these platforms were subsequently posted online, along with over 500,000 private messages exchanged between users.

The exposure of sensitive personal and communication data from matrimony-focused platforms created significant privacy risks for affected individuals. Clear-text password storage at Shadi.com enabled immediate credential misuse, while MD5-hashed passwords from MuslimMatch remained vulnerable to cracking attempts. Security analysts observed parallels with contemporaneous breaches at AfrikaDating.com, AdultSingleSites.com.au, and PinkDate.co.uk, where thousands of additional user records were leaked. Leaked Source publicly confirmed possession of the datasets but did not disclose acquisition methods. Users received advisories to proactively secure online accounts through password managers capable of generating unique credentials, thereby limiting cross-service compromise risks from reused passwords. Shadi.com's operators were contacted for comment following the breach disclosure, though no further operational details or mitigation measures were publicly confirmed at the time of reporting.

Sources

Sources available to members: 1 source.

CSIDB