Naughty America 2016 Data Breach

Naughty America Adult Entertainment Platform Breach (2016): 1.3 Million Subscriber Accounts Including DOB & Website Activity Exposed

Company · Premium adult video production and distribution · Subscription-based streaming platform · Global

Naughty America Adult Entertainment Platform Breach (2016): 1.3 Million Subscriber Accounts Including DOB & Website Activity Exposed

Naughty America is a major adult entertainment brand producing and distributing professional video content. The platform operates on a subscription-based model, granting users access to a large catalog of studio-produced material. User accounts are tied to payment systems, viewing history, and content preferences. // Exposed data includes Email;Dates of birth, Email, IP addresses, Passwords, Usernames, Website activity. High sensitivity. Elevated risk of extortion, reputational damage, and identity linkage.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly. Use the private exposure check at the bottom of this page.
Breach Risk Index i
65/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
1.3MRecords
2016Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
Peace / peace_of_mindViceAdult2016

Breach Summary

Naughty America, a major adult-entertainment subscription platform operated by La Touraine, Inc., suffered a data breach disclosed in spring 2016. A threat actor using the alias Peace advertised the stolen database for sale on the dark-web market The Real Deal at a price of approximately $300, an unusually low valuation for a multi-million-record dataset.\n\nThe threat actor claimed approximately 3.8 million user accounts were compromised across Naughty America and affiliated platforms including the gay-content site Suite703 and related community forums. Have I Been Pwned subsequently indexed approximately 1.4 million unique email addresses from the dataset. Exposed fields included usernames, email addresses, dates of birth, IP addresses, passwords stored largely as MD5 hashes, and website activity records covering subscription and content interaction. No financial-account data has been publicly tied to the leak.\n\nFor affected individuals, the practical risk extends well beyond standard credential exposure. The combination of email, date of birth, and account activity records creates a base for blackmail, extortion, and reputational harm tied to documented adult-platform participation. Anyone who used Naughty America or any of its affiliated sites should not respond to unsolicited extortion or blackmail attempts referencing the breach. Such messages are typically mass-targeted and rely on victims paying out of fear. Law enforcement and victim-support resources are the appropriate first point of contact rather than the sender of any such message. Customers should also rotate passwords on any service where the same credentials were reused.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

1.3M records analyzed

About Naughty America

Naughty America is a major adult-entertainment brand operated by La Touraine, Inc., based in San Diego, California. The company produces and distributes professional adult video content through a subscription-based streaming platform and a network of affiliated sites that share account infrastructure. User accounts are tied to payment processing, viewing history, content preferences, and forum activity. The platform serves a global audience and has operated continuously since the early 2000s. Affiliated brands historically associated with the same account systems include the gay-content site Suite703 and various community forums.

Why They Hold Your Data

Subscription adult-content platforms collect highly sensitive account data, emails, usernames, payment-adjacent records, and viewing or subscription activity tied to explicit-content access.

Recent Developments

Naughty America has continued to operate as an adult-content publisher since the 2016 breach. The company has not been publicly tied to a further major data breach disclosure. The 2016 dataset has periodically resurfaced on dark-web markets and breach-tracking aggregators, with the public-facing record updated by HIBP and DataBreach.com in 2025 as part of broader indexing of legacy adult-platform leaks. The wider adult-platform sector has continued to draw attention from researchers as one of the most consistently targeted categories for credential theft and extortion-driven attacks.

Data Points Exposed

6 verified field types
Activity History
Date of Birth High
Email Address
IP Address
Password High
Username

Breach Impact

Direct institutional cost to Naughty America from the 2016 incident has been limited. There is no public record of substantial regulatory action, class-action settlement, or large-scale customer-notification campaign tied specifically to the breach. The company's privacy policy, which did not commit to deleting user data on subscription cancellation, drew critical press attention at the time of the disclosure. The lasting impact has been reputational and operational, with Naughty America cited alongside Adult FriendFinder and Ashley Madison as a reference incident in industry discussion of adult-platform privacy. The fact that the data was offered for sale at unusually low cost reflected weak market valuation of the records.

Exploitation & Downstream Threats

• Credential stuffing against reused passwords across other platforms | • Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

An intimate-data breach: preferences, orientation or explicit content linked to an identity create acute coercion and blackmail exposure. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Reset any reused passwords and enable MFA on email first, then financial accounts.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
P/
Threat Actor: Peace / peace_of_mindConfidence: High
Data seller / breach broker

Motivation: Financial
A breach seller associated with major credential datasets in 2016, including Myspace, LinkedIn, and Tumblr-related data. Public reporting often treats Peace as a seller or broker rather than necessarily the original intruder for each dataset.

Read the full threat-actor profile →

Protect Yourself

Protect Yourself: Limited Disclosure

Check If You’re Affected: Verification Required

Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.

We will only reveal whether a specific person appears in this breach to that person.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation