On July 15, 2015, a group calling themselves the Impact Team announced they had compromised Avid Life Media, the parent company of Ashley Madison - a dating site explicitly marketed to people seeking extramarital affairs. The group posted a small sample of stolen data and issued an ultimatum: shut down Ashley Madison and sister site Established Men within 30 days, or the full database would be released. The database contained the real names, home addresses, email addresses, and sexual preferences of 37 million registered users.
Avid Life Media did not shut down the sites. On August 18, 2015, the Impact Team released approximately 10 gigabytes of data on the dark web. A second release followed days later. The breach became one of the most consequential in terms of human harm - not financial damage to a corporation, but direct, immediate, personal consequences for tens of millions of individuals.
What Was in the Database
The released data included: names, email addresses, hashed passwords, home and work addresses, phone numbers, the last four digits of credit card numbers, transaction histories, GPS coordinates from mobile app use, and detailed profile fields including body type, sexual fantasies, and what users were "open to." For users who had paid for Ashley Madison's "Full Delete" service - a $19 feature that promised complete removal of their account and data - their records were still present in the database.
The email addresses included addresses from US government domains (.gov and .mil), the UK's National Health Service, and major corporations. Researchers analyzing the data identified addresses belonging to military officers, politicians, and executives. The data also revealed that the vast majority of active female profiles were either fake or bots - internal company data included in the breach showed that fewer than 1,500 of the women in the database had ever sent a message, while millions of male accounts had.
The Extortion Wave
Within days of the data release, extortion emails began arriving in inboxes. The pattern was consistent: "I know you were on Ashley Madison. Pay X in Bitcoin to [address] within 7 days or I send this to your wife/employer/church." Most demands were for $500 to $2,000. The scale was massive - researchers estimated hundreds of thousands of extortion attempts in the weeks following the release.
The extortion letters were not necessarily sent by anyone who had verified the target was actually a user. Many were mass-sent to anyone whose email appeared in the database, regardless of whether the account had ever been active or whether the email address had been registered by someone else (Ashley Madison did not verify email addresses at signup). A person whose email was used without their knowledge to create an account received the same extortion letters as actual users.
The emotional consequences were severe and immediate. Security researchers documented suicides attributed to the breach within weeks of the data release. Two people in Canada were identified as having taken their own lives following exposure. A pastor in New Orleans who had counseled others through marital problems took his own life after his name appeared in the data. The number of suicides with any causal link to the breach was likely larger, as most went undocumented.
The Fake Profiles Problem
Post-breach analysis by Annalee Newitz at Gizmodo revealed that of the approximately 5.5 million female accounts in the database, the vast majority showed no human activity. Automated scripts had created fake profiles using stock images. Internal company documents showed Ashley Madison's own employees had created thousands of "fembots" - automated accounts designed to engage male users, keep them subscribed, and drive credits purchases for messaging. The company had received internal reports flagging the scale of the fraud before the breach.
This finding reshaped the narrative. Many of the 37 million "users" were men who had paid for a service that systematically deceived them about the existence of real women on the platform. The moral framing of "cheaters getting what they deserve" became more complicated when the cheaters had largely been cheated by the platform they were using.
Attribution and Investigation
The Impact Team was never definitively identified or prosecuted. The group's stated motivation was moral - they objected to Ashley Madison's business model, specifically the Full Delete fraud and the exploitation of lonely married men via fake profiles. This framing positioned them as vigilantes rather than typical data thieves seeking financial gain.
Several indicators suggested an insider. The breach included internal Avid Life Media documents, executive emails, source code, and database schemas - the kind of comprehensive internal access that is difficult to achieve purely through external exploitation. Toronto Police investigated. Brian Krebs, who was first informed of the breach by the Impact Team, noted that the group appeared to have had sustained access to internal systems. No arrest was made.
The CEO of Avid Life Media, Noel Biderman, resigned on August 28, 2015, ten days after the initial data dump. His own emails, included in the breach, showed he had been aware of security vulnerabilities and had engaged in his own extramarital affairs - somewhat undermining his company's brand positioning.
Legal Aftermath
Avid Life Media, rebranded as Ruby Corp, settled class action lawsuits in multiple jurisdictions. The $11.2 million US settlement compensated verified users for the breach. The FTC and state attorneys general investigated the fake profile practices. In 2016, Ruby Corp settled with the FTC over deceptive practices including the fembots and the misleading Full Delete feature - without admitting liability, paying no fine, but agreeing to a consent decree requiring proper security practices and prohibition of fake profiles.
The settlement amounts, divided among 37 million potential claimants, resulted in de minimis individual payments - a few dollars per verified user. The legal process was largely symbolic. What the breach demonstrated more durably was that the combination of sensitive personal data, deceptive business practices, and inadequate security created a category of harm that courts and regulators had not developed adequate frameworks to address. Financial penalties calibrated to corporate revenue rather than individual harm left the actual victims without meaningful remedy.