Adult FriendFinder 2015 Data Breach

AdultFriendFinder Platform Breach (2015): 3.6 Million User Accounts Including Sexual Orientation & Location Exposed

Company · Online dating and adult social platforms · Network of niche social platforms · Global

AdultFriendFinder Platform Breach (2015): 3.6 Million User Accounts Including Sexual Orientation & Location Exposed

Adult-oriented dating and entertainment platform.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly. Use the private exposure check at the bottom of this page.
Breach Risk Index i
65/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
3.6MRecords
2015Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
IntimateSexual Orientation
Classification Tags
ROR[RG]Web Application ExploitViceAdultUsers2015

Breach Summary

Adult FriendFinder, a major adult-oriented dating site operated by U.S.-based FriendFinder Networks, suffered a data breach in May 2015 attributed to a hacker using the alias ROR[RG]. The attacker initially sought a $100,000 ransom and then made the data publicly available when the demand was not met. The leaked dataset covered approximately 3.6 million user accounts.\n\nThe exposed records were unusually sensitive even by dating-site standards. Fields included email addresses, usernames, IP addresses, dates of birth, gender, race, spoken language, geographic location, relationship status, and stated sexual orientation. Many of the user-stated preferences were specific and identifying. The breach was the precursor to a much larger 2016 incident at the same company that exposed more than 412 million records across the broader FriendFinder Networks platform portfolio.\n\nFor affected individuals, the practical risk extends well beyond standard credential-reuse and phishing. The combination of identifiable contact data with self-reported sexual orientation and relationship status creates serious blackmail, extortion, doxxing, and outing risks. People in environments where their orientation, marital status, or activity could lead to personal, professional, or physical harm face the most acute exposure. Anyone who used the site should not respond to any extortion or blackmail attempt referencing the breach. Such messages are typically mass-targeted and rely on victims paying out of fear. Law enforcement and established victim-support and LGBTQ+ advocacy organizations should be the first point of contact rather than the sender of any such message.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

3.6M records analyzed

About Adult FriendFinder

Adult FriendFinder is the flagship adult-oriented dating and social-platform service operated by FriendFinder Networks, a U.S.-based parent company that runs a portfolio of related sites including Cams.com, Penthouse.com, and Stripshow.com. The platform is positioned as a community for casual hookups, swinging, and adult relationships, and it has been one of the larger services of its kind on the open web. The site collects unusually sensitive profile data including stated sexual orientation, relationship status, demographic markers, and geographic location to support its matching features.

Why They Hold Your Data

Adult dating and hookup services collect highly sensitive profile information including identity markers, sexual preferences, relationship status, demographic attributes, location indicators, and participation data.

Recent Developments

FriendFinder Networks suffered a much larger second breach in October 2016, which exposed more than 412 million accounts across its full portfolio of adult sites and is regarded as one of the largest breaches of its era. That incident dwarfed the 2015 disclosure in scale and reset public attention on the company. FriendFinder Networks remains operational, although its public profile in cybersecurity reporting has been defined by these two incidents. The company's password-storage and data-retention practices have been the subject of sustained criticism from researchers, including the discovery that supposedly deleted user records were retained indefinitely.

Data Points Exposed

10 verified field types
Date of Birth High
Email Address
Ethnicity Or Race
Gender
Geographic location
IP Address
Relationship Status
Sexual Orientation High
Spoken Language
Username

Breach Impact

The 2015 incident produced limited regulatory penalty by current standards but significant reputational damage, and it contributed to a broader narrative of weak security culture at FriendFinder Networks that was reinforced by the much larger 2016 breach. There is no public record of substantial fines or class-action settlement tied specifically to the 2015 incident. Operationally, the company faced press scrutiny and forced password resets across the user base. The lasting institutional cost has been a sustained loss of trust among privacy-aware users and ongoing referencing of the incident in cybersecurity literature as an example of how adult-platform breaches inflict particular kinds of personal harm.

Exploitation & Downstream Threats

• Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure

Principal Risk Advisory

What this means for a principal

An intimate-data breach: preferences, orientation or explicit content linked to an identity create acute coercion and blackmail exposure. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Be alert to sextortion or blackmail attempts referencing this data and do not engage; preserve and report messages.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
R
Threat Actor: ROR[RG]Confidence: Medium
Hacker / leak actor

Motivation: Unclear, possibly political or financial
A hacking and leak actor reported in connection with several high-profile breaches, including the 2016 Turkish National Police leak. Public sourcing is thinner than for major ransomware groups, so incident-specific sourcing is important.

Read the full threat-actor profile →

Protect Yourself

Protect Yourself: Limited Disclosure

Check If You’re Affected: Verification Required

Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.

We will only reveal whether a specific person appears in this breach to that person.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation