Shadi.com 2016 Data Breach

Shadi.com Muslim Matrimonial Platform Breach (2016): 2 Million User Accounts Including Plaintext Passwords Exposed

Platform · Matrimonial and matchmaking services · Online relationship platform · India / Global

Shadi.com Muslim Matrimonial Platform Breach (2016): 2 Million User Accounts Including Plaintext Passwords Exposed

Matrimonial matching site (Muslim community).

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly.
Breach Risk Index i
44/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
2.0MRecords
2016Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
Dating & RelationshipsDating2016

Breach Summary

In July 2016, the matrimonial site Shadi.com suffered a data breach exposing about 2.03 million member records, comprising email addresses and passwords stored as MD5 hashes alongside their plaintext equivalents. HIBP marks the breach as sensitive and it is not publicly searchable.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

2.0M records analyzed

About Shadi.com

Shadi.com is a web-based Muslim marriage-introduction service that connects men and women in the UK, United States, Canada, and other countries who are seeking marriage. It operates in the matrimonial/matchmaking category rather than casual dating, and historically positioned itself around protecting member contact information to prevent unwanted communication. It should not be confused with Shaadi.com, the larger India-based People Group matrimonial platform; the two are unrelated entities that share a similar name. As a matchmaking service, Shadi.com collects email addresses, account credentials, profile details, and relationship-intent information tied to a religiously identifiable user base.

Why They Hold Your Data

Matrimonial platforms collect highly sensitive profile data, family details, religion or caste-related attributes, photos, messages, and relationship-intent records tied to matchmaking workflows.

Recent Developments

No significant public developments have been reported for Shadi.com since the 2016 breach; the service has maintained a low public profile and issued no substantial breach communications of record. The breach data continued to circulate through breach-aggregation and credential-search services (Have I Been Pwned, LeakedSource, and numerous mirror catalogues) in the years following disclosure, and HIBP added the dataset to its index in July 2022, flagging it as sensitive and not publicly searchable. Because the exposed credentials were stored in plaintext, the data remains directly usable for credential stuffing wherever affected members reused passwords, keeping the record operationally relevant nearly a decade later.

Data Points Exposed

2 verified field types
Email Address
Password High

Breach Impact

Plaintext-equivalent passwords enable immediate account access and stuffing; association with a religious matrimonial site adds sensitivity (inferred religion/relationship status).

Exploitation & Downstream Threats

• Credential stuffing against reused passwords across other platforms | • Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

An intimate-data breach: preferences, orientation or explicit content linked to an identity create acute coercion and blackmail exposure. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Reset any reused passwords and enable MFA on email first, then financial accounts.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation