Ashley Madison's leaked database available for download - read this first

Ashley Madison database download

What's happened?
As I'm sure you'll remember, popular adultery website Ashley Madison got hacked in July. The hackers - who went by the name of the Impact Team - demanded that its owners, Avid Life Media, shut the site down and sister sites including Cougar Life and Established Men.

If their demands weren't met, the hackers threatened to release details of some 37 million Ashley Madison users.

And then?
Nothing. Well, Ashley Madison didn't shut down at least. Maybe some members tried to delete their accounts in panic (although that was rather like closing the door after the horse had bolted), and Avid Life Media generously decided to start offering account removals for free rather than charging $15.

So why are you writing about this again now?
Because people claiming to be the Impact Team have released what they say is the database of Ashley Madison users on torrent sites, available for anyone in the internet to download.

Ashley madison leak

That sounds bad. Is it?
Chances are that many people who are members of the Ashley Madison website will feel uncomfortable with their boss, friends, partner or mother-in-law knowing about it. So they probably won't be happy if the leaked database is genuine.

It's easy to imagine that some people might be vulnerable to blackmail, if they don't want details of their membership or sexual proclivities to become public.

Check out my video below where I discuss the threat of blackmail following the Ashley Madison breach, and feel free to subscribe to my YouTube channel.

Others might find the thought that their membership of the site - even if they never met anyone in real life, and never had an affair - too much to bear, and there could be genuine casualties as a result.

And yes, I mean suicide.

But if they're in the Ashley Madison website, don't they deserve what's coming to them?
No.

For one thing, being a member of a dating site, even a somewhat seedy one like Ashley Madison, is no evidence that you have cheated on your partner.

You might have joined the site years before when you were single and be shocked that they still have your details in their database, or you might have joined the site out of curiosity or for a laugh or even to find out if someone else was on the site... never seriously planning to take things any further.

But more importantly than all of that, if your email address is in the Ashley Madison database it means nothing. The owner of that email address may never have even visited the Ashley Madison site.

As Per Thorsheim explained in an article last month, Ashley Madison *never* bothered to verify the email addresses given to it by users.

So, I could have created an account at Ashley Madison with the address of barack.obama@whitehouse.gov, but it wouldn't have meant that Obama was a user of the site. (Apologies to Michelle for any concern I may have caused her by mentioning her husband's name in relation to this article - I'm sure he has more important things to do with his time than to join online dating sites, anyway)

Journalists and commentators would be wise to remember that the credentials stored by Ashley Madison must be considered suspect because of their shonky practices, even before you start considering whether any leaked databases are falsified or not.

Further reading:

Tags: , ,

Smashing Security podcast
Check out "Smashing Security", the new weekly audio podcast, with Graham Cluley, Carole Theriault, and special guests from the world of information security.

"Three people having fun in an industry often focused on bad news" • "It's brilliant!" • "The Top Gear of computer security"

Latest episode:

Subscribe to the free GCHQ newsletter

, ,