Adult FriendFinder 2016 Data Breach

AdultFriendFinder Network Breach (2016): 220 Million Adult Platform User Accounts Including Passwords Exposed

Company · Online dating and adult social platforms · Network of niche social platforms · Global

AdultFriendFinder Network Breach (2016): 220 Million Adult Platform User Accounts Including Passwords Exposed

Adult-oriented dating and entertainment platform.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly. Use the private exposure check at the bottom of this page.
Breach Risk Index i
65/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
220.0MRecords
2016Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
Cloud MisconfigurationViceAdultUsers2016

Breach Summary

Friend Finder Networks, the operator of Adult FriendFinder and five related platforms including Cams.com and Penthouse.com, suffered one of the largest data breaches ever recorded on a dating service. Attackers exploited a Local File Inclusion vulnerability in a company web application, which allowed them to read server configuration files and reach production databases. The breach exposed approximately 412 million account records across the FriendFinder portfolio, with around 339 million tied to Adult FriendFinder alone. After removing duplicates, roughly 220 million unique email addresses were affected. The stolen data was traded privately on underground forums before appearing in public breach-notification services in early 2020. The exposed records included usernames, email addresses, passwords, IP logs, and spoken-language settings. Critically, 99 percent of passwords were stored either in plain text or using unsalted SHA-1, a weak hashing method that is trivially easy to reverse. The breach also surfaced approximately 15 million accounts that users had deleted but that Friend Finder Networks had never actually removed from its systems. Because the platform is adult-oriented, the combination of email addresses and cracked passwords carries a heightened risk. Affected individuals face potential extortion and sextortion attempts, even if they never engaged in explicit activity, simply because their email address is tied to a known adult platform. Friend Finder Networks did not publicly disclose the breach through formal regulatory channels in a timely manner, and no widely reported civil or criminal enforcement action followed. The cracked credential lists circulated quickly after the data became public, fueling credential-stuffing attacks against unrelated sites where users had reused the same passwords. Anyone whose email address appears in this breach should treat that password as fully compromised, change it anywhere it was reused, and remain alert to blackmail or phishing attempts that reference their Adult FriendFinder account.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

220.0M records analyzed

About Adult FriendFinder

Adult FriendFinder is an adult-oriented dating and social networking platform operated within the FriendFinder Networks portfolio. The service has long been built around profiles, messaging, sexual-interest matching, and community interaction for adult users seeking hookups, swinger connections, and other explicit relationship or lifestyle activity.

Why They Hold Your Data

Adult hookup platforms collect emails, usernames, passwords, profile language preferences, and relationship or sexual-interest-linked account data across large user communities.

Recent Developments

Adult FriendFinder remains active as part of FriendFinder Networks, which publicly says it is in a modernization phase under founder Andrew Conru’s renewed ownership and CEO Brock Purpura’s leadership. Current company materials describe a member-first strategy, leadership changes in 2024, and a broader effort to update the platform and its surrounding network of adult and dating properties.

Data Points Exposed

4 verified field types
Email Address
Password High
Spoken Language
Username

Breach Impact

The 2016 breach was one of the largest and most sensitive dating-platform exposures ever reported, affecting hundreds of millions of accounts across Adult FriendFinder and related FriendFinder properties. Public reporting and breach tracking say the exposed data included usernames, email addresses, passwords, site-usage metadata, and records tied to adult-oriented accounts, with many passwords stored in plain text or weakly hashed and with some supposedly deleted accounts still present. That made the breach especially serious because it enabled credential stuffing and account takeover, while also creating elevated risks of extortion, humiliation, outing, and highly targeted phishing tied to sexual-interest data.

Exploitation & Downstream Threats

• Credential stuffing against reused passwords across other platforms | • Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

An intimate-data breach: preferences, orientation or explicit content linked to an identity create acute coercion and blackmail exposure. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Reset any reused passwords and enable MFA on email first, then financial accounts.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Protect Yourself: Limited Disclosure

Check If You’re Affected: Verification Required

Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.

We will only reveal whether a specific person appears in this breach to that person.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation