Company · Online dating and adult social platforms · Network of niche social platforms · Global
Adult-oriented dating and entertainment platform.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Adult FriendFinder, a major adult-oriented dating site operated by U.S.-based FriendFinder Networks, suffered a data breach in May 2015 attributed to a hacker using the alias ROR[RG]. The attacker initially sought a $100,000 ransom and then made the data publicly available when the demand was not met. The leaked dataset covered approximately 3.6 million user accounts.\n\nThe exposed records were unusually sensitive even by dating-site standards. Fields included email addresses, usernames, IP addresses, dates of birth, gender, race, spoken language, geographic location, relationship status, and stated sexual orientation. Many of the user-stated preferences were specific and identifying. The breach was the precursor to a much larger 2016 incident at the same company that exposed more than 412 million records across the broader FriendFinder Networks platform portfolio.\n\nFor affected individuals, the practical risk extends well beyond standard credential-reuse and phishing. The combination of identifiable contact data with self-reported sexual orientation and relationship status creates serious blackmail, extortion, doxxing, and outing risks. People in environments where their orientation, marital status, or activity could lead to personal, professional, or physical harm face the most acute exposure. Anyone who used the site should not respond to any extortion or blackmail attempt referencing the breach. Such messages are typically mass-targeted and rely on victims paying out of fear. Law enforcement and established victim-support and LGBTQ+ advocacy organizations should be the first point of contact rather than the sender of any such message.
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
3.6M records analyzed
Adult FriendFinder is the flagship adult-oriented dating and social-platform service operated by FriendFinder Networks, a U.S.-based parent company that runs a portfolio of related sites including Cams.com, Penthouse.com, and Stripshow.com. The platform is positioned as a community for casual hookups, swinging, and adult relationships, and it has been one of the larger services of its kind on the open web. The site collects unusually sensitive profile data including stated sexual orientation, relationship status, demographic markers, and geographic location to support its matching features.
Adult dating and hookup services collect highly sensitive profile information including identity markers, sexual preferences, relationship status, demographic attributes, location indicators, and participation data.
FriendFinder Networks suffered a much larger second breach in October 2016, which exposed more than 412 million accounts across its full portfolio of adult sites and is regarded as one of the largest breaches of its era. That incident dwarfed the 2015 disclosure in scale and reset public attention on the company. FriendFinder Networks remains operational, although its public profile in cybersecurity reporting has been defined by these two incidents. The company's password-storage and data-retention practices have been the subject of sustained criticism from researchers, including the discovery that supposedly deleted user records were retained indefinitely.
The 2015 incident produced limited regulatory penalty by current standards but significant reputational damage, and it contributed to a broader narrative of weak security culture at FriendFinder Networks that was reinforced by the much larger 2016 breach. There is no public record of substantial fines or class-action settlement tied specifically to the 2015 incident. Operationally, the company faced press scrutiny and forced password resets across the user base. The lasting institutional cost has been a sustained loss of trust among privacy-aware users and ongoing referencing of the incident in cybersecurity literature as an example of how adult-platform breaches inflict particular kinds of personal harm.
• Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure
An intimate-data breach: preferences, orientation or explicit content linked to an identity create acute coercion and blackmail exposure. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Unclear, possibly political or financial
A hacking and leak actor reported in connection with several high-profile breaches, including the 2016 Turkish National Police leak. Public sourcing is thinner than for major ransomware groups, so incident-specific sourcing is important.
Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.
We will only reveal whether a specific person appears in this breach to that person.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation