Hackers calling themselves the Impact Team said they had breached Avid Life Media, the Toronto-based owner of the Ashley Madison dating website, in a claim first reported by KrebsOnSecurity on 19 July 2015. They threatened to publish customer records unless the company shut the site down.
What happened
- The attackers claimed data on around 37 million users and criticised the site’s paid “full delete” service, alleging that personal details were retained after users paid to be removed.
- In August 2015 the group published large volumes of user records and internal company data online.
- Criminals then sent extortion emails to people whose details appeared in the leak, typically demanding payment in bitcoin to stay silent.
- In August 2016 the Privacy Commissioner of Canada and the Australian Information Commissioner found serious security shortcomings, including weak authentication for remote access and poor key and password management, and said a fabricated security trustmark on the site was deceptive; the company entered a compliance agreement and enforceable undertaking.
Why it mattered
The breach showed that the harm from exposing sensitive personal data extends far beyond financial loss, and that retaining data users believe has been deleted multiplies that harm.
Lessons for organisations
Match security controls to the sensitivity of the data you hold, honour deletion promises in practice, and never make security claims to customers that you cannot substantiate.
Sources: KrebsOnSecurity, Office of the Privacy Commissioner of Canada
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.