Large online dating site AdultFriendFinder confirms data breach


Userlevel 7
Badge +54
21st May 2015 

 
Mike Snider reports:
One of the largest online dating sites, the 64 million-member AdultFriendFinder.com, has contacted law enforcement and high-profile security firm FireEye to investigate a data breach.
 
Information including sexual preference, marital status and other personal data (dates of birth, email addresses and addresses) for as many as 4 million members may have been stolen, according to U.K. news agency Channel 4, which first reported the incident.
 
Full Article

5 replies

Userlevel 7

Posted on 22 May 2015.Information of over 3.5 million users of dating site Adult FriendFinder has been stolen and leaked online, and is being used by spammers, scammers and phishers, a Channel 4 investigation into the Deep Web has revealed.

According to a researcher known as Teksquisite, the leak was published in mid-April, and consists of 15 spreadsheets containing user information such as name, email address, online handle, password, marital status, sex, race, date of birth, sexual preferences, IP address, country/state, ZIP code, and so on. Credit card data is not included.

Apart from being perfect for personalizing phishing emails, Teksquisite notes that the data can be, in many cases, tied to the users' real-life identities.

"You can assume that the hacked database is not simply sitting on one forum — it is probably being shared within other Darknet and I2P forums too. With so much data included in the rooted database(s), and even though the majority of email addresses come from free email accounts such as AOL, Gmail, Live, Hotmail, and Yahoo.com — it should be relatively easy to dox a slew of them," she added. full article
Userlevel 7
Badge +54
By Ionut Ilascu    25 May 2015
 

A version of the database is distributed via social media

 
http://i1-news.softpedia-static.com/images/news2/Full-Adult-Friend-Finder-Database-Up-for-Sale-for-70-Bitcoins-482157-2.jpg
 
Personal information of about 3.9 million members of Adult Friend Finder online hookup service, is currently for sale for 70 bitcoins ($16,800 / €15,300) on an underground website.
 
The details about the subscribers are stored in 15 Excel spreadsheets, and contain email addresses, usernames, dates of birth, postal codes, sexual orientation, gender, and IP addresses, a treasure trove for spammers and phishing.
 
The website has been breached before April 13 and the database (possibly withholding some information) has been available on a forum hidden in Tor anonymity network, which is accessible through Tor web browser.
 
However, since Channel 4 broke the news on Thursday, the files started to be distributed via social media sites on the regular Internet.
 
Full Article
Userlevel 7
Yeppers, I caught the Channel Four piece and that was surprising that it even made the national news...as generally this sort of thing either never gets reported or if it does then it is several days or even weeks after it has broken in the specialist press.
 
Having said that, why it should be covered when I would expect the majority of the news reading public would have little or nothing to do with the source site in the first place, is a bit of a mystery to me.
 
Baldrick
Userlevel 7
These cyber criminals have a gold mine with all this data at their finger tips. Now you would think this dating service would have enough sense to have tight security on their system.
Userlevel 7
By Jeremy Kirk
 
An unredacted version of a database said to be stolen from Adult Friend Finder is being offered for sale for 70 bitcoins, or around $17,000.
ROR[rg], the nickname of the person who claims to have breached the large online hookup site, wrote on Saturday in an underground forum that "I have had so many people ask me to buy the db today."
Seeking to capitalize on the momentum, ROR[rg] -- who claims to live in Thailand -- also offered to break into any company or website for 750 bitcoins, worth about $170,000.
Fifteen files of data purported to come from Adult Friend Finder were posted to an underground forum in March. The files contained 3.9 million email addresses and in some cases the partner preference, gender, birth date, state, post code, language preference and IP address of users.
 
full article

Reply