Case file · ASHLEY MADISON 2015

How the Ashley Madison hack happened: a stolen login and a one-factor VPN

Published 2026-09-29 · 4 min read · Missing control: MFA on remote access

Ashley Madison sold members a $19 "Full Delete" that was supposed to erase them, then kept their data for up to a year anyway.[1][2] In 2015 an attacker walked in through the company's remote-access door with an employee's login and took all of it. This case file covers how the break-in worked, what regulators found once they looked inside, what it cost, and the one control that would have made the stolen login useless.

What happened

Ashley Madison was a dating site for people who were married or in relationships, run by a Toronto company then called Avid Life Media, with about 100 staff at headquarters and revenue above $100 million in 2014.[2] On July 12, 2015, its IT staff spotted someone accessing a database without permission. The next day, a message from the attackers appeared on employees' computers.[2]

On July 19 a group calling itself the Impact Team announced the hack publicly and demanded the site shut down. The company reported the breach to Canada's privacy regulator on July 20.[2] The site stayed up, and between August 18 and 20, 2015, the stolen data was published online.[2]

The dump covered about 36 million accounts from users in more than 46 countries, roughly 19 million of them in the United States.[1] For a service built on discretion, it was the worst possible outcome, and it hit people who had already paid to leave.

How they got in

According to the joint investigation by the privacy commissioners of Canada and Australia, the attacker used an employee's compromised credentials to log in to the company's virtual private network, or VPN, the tunnel staff used to reach internal systems from outside the office.[2] From there the intruder gained administrator rights, deleted logs to hide their tracks, and stayed inside for at least several months before anyone noticed.[2] The investigators described it as a targeted attack by a sophisticated intruder, not a random one.[2]

The VPN looked like it had several locks: a username, a password, a shared secret, a group name and a server address. But every one of those was something a person knows, which makes it a single factor in security terms. Worse, the shared secret sat in a company Google Drive folder that any employee could open.[2] Once someone had one worker's password, the rest was easy to find.

Inside, the picture was similar. Investigators found encryption keys and passwords stored as plain text on company systems, no documented information security policy, and no intrusion detection or central log monitoring. Only about 25% of staff had received security training when the breach happened.[2] The FTC separately found that intrusions between November 2014 and June 2015 had gone undetected.[1]

The member passwords themselves were mostly hashed with a strong algorithm, though some older ones used weaker methods.[2] The problem was never one weak spot. It was that a single stolen login opened a network with almost nothing watching it.

What it cost

The Canadian and Australian regulators found multiple violations of both countries' privacy laws. The company signed a compliance agreement in Canada and an enforceable undertaking in Australia, and hired its first Chief Information Security Officer in October 2015.[2]

The regulators also looked closely at Full Delete. Canadian users paid C$19 for it, and it removed profiles from view within a day or two, but the company kept the underlying information for 12 months, later cut to 6. Users only learned about the retention after paying.[2] The homepage had also shown a "trusted security award" badge that investigators called the company's own invention.[2]

On December 14, 2016, the operators settled with the FTC, 13 states and the District of Columbia. The judgment was $8.75 million, but the company paid $1.6 million, split between the FTC and the states, with the rest suspended.[1] The FTC also alleged the site had used fake profiles of women to convert men into paying members, and the order required a full data security program with outside assessments.[1]

The missing control

The missing control: multifactor authentication on remote access. The VPN let anyone with the right typed-in details onto the network, no matter where they were or what device they used.

A second factor that a thief cannot simply read, such as a code from a phone app or a physical security key, would have turned the compromised employee credentials into a dead end. The shared secret in the open Drive folder would not have mattered, because knowing it would not be enough. Better monitoring would likely have shortened the months the intruder spent inside, but stronger login at the front door is what would have kept them out in the first place.[2]

What to do in your business

Watch the case
Ashley Madison charged $19 to delete data it keptDrops 2026-12-06
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Federal Trade Commission: Operators of AshleyMadison.com settle FTC, state charges resulting from 2015 data breach that exposed 36 million users' profile information
  2. Office of the Privacy Commissioner of Canada: Joint investigation of Ashley Madison by the Privacy Commissioner of Canada and the Australian Privacy Commissioner (PIPEDA Report of Findings #2016-005)