412 Million Adult-Site Accounts Bared in Data Breach

More than 412 million usernames, email addresses and passwords for user accounts associated with top adult-entertainment and dating websites have been exposed, thanks to a massive intrusion last month into the databases of the FriendFinder network, which runs AdultFriendFinder.com, Penthouse.com, Stripshow.com, Cams.com and iCams.com. User data from a sixth, unidentified, site was also affected.

Image: Andrey_Popov / Shutterstock.com

Image: Andrey_Popov / Shutterstock.com

FriendFinder stored user passwords in either plain text or as "hashes," strings of seemingly random letters and numbers that are the results of running passwords through complex mathematical algorithms. Sadly, the hashing algorithm used by FriendFinder wasn't very strong. About 99 percent of the 412 million FriendFinder passwords have been cracked, according to LeakedSource, a controversial website that obtained and analyzed the full data set.

If you've ever created an account on any of the FriendFinder sites, and you reused that password on other websites, change that password on the other sites immediately. If you deleted an account on a FriendFinder site months or years ago, sorry — it looks like the company kept your user records on the books anyway.

MORE: What to Do After a Data Breach

The FriendFinder databases have circulated online since the leak, and some records have time stamps from as recently as Oct. 17, so it's assumed the intrusion took place in the latter half of last month. A security researcher using the online name 1x0123 reportedly warned FriendFinder of a security flaw on Oct. 18th and FriendFinder responded that it would investigate the claims.

Even if you create a long, complicated, hard-to-guess password, it can still be cracked if a company stores it improperly — LeakedSource says that passwords of up to 32 characters were cracked in this instance. Even worse, FriendFinder seems to have converted all letters in passwords to lowercase before hashing them, making reversing the hashes much easier.

Ironically, that means users whose passwords mixed uppercase and lowercase letters are slightly safer, as malicious hackers may have a hard time guessing which letters would have originally been uppercase.

FriendFinder users who deleted their accounts prior to this breach are still affected. LeakedSource notes that a "significant amount of users had an email in the format of: email@address.com@deleted1.com." Websites sometimes do this to retain user information even after a user requests to be purged from the rolls.

How significant is the amount of users who tried to delete themselves? 15,766,727 user records include "@deleted" in the email field. So even if you felt guilty about using the service and abandoned it, it still kept your email address on file.

LeakedSource normally lets you search for your own email address for free, then charge you for further information. (Similar sites give you full access for free.) But it isn't giving the public access to the FriendFinder data set yet, citing "much internal deliberation" and "various reasons." We're guessing that it doesn't want to make it easy to search for the email addresses of your spouse, friends, foes or family members.

So what can you do?

— Never recycle your password. Reusing a password across multiple sites means that all those sites get put at risk when one service is hacked.

— Instead, use a password manager to create unique, complex, hard-to-guess passwords for each service you use. Mix upper and lowercase characters and use numbers and other symbols.

— We're not judging what you do online, but think twice before you do anything on the internet. Most online services will suffer data breaches eventually, and privacy is more a temporary state of mind than something you can believe in.

TOPICS
Henry T. Casey
Managing Editor (Entertainment, Streaming)

Henry is a managing editor at Tom’s Guide covering streaming media, laptops and all things Apple, reviewing devices and services for the past seven years. Prior to joining Tom's Guide, he reviewed software and hardware for TechRadar Pro, and interviewed artists for Patek Philippe International Magazine. He's also covered the wild world of professional wrestling for Cageside Seats, interviewing athletes and other industry veterans.

Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Latest in News
Galaxy S25 Ultra Now brief
Samsung’s Personal Data Engine is a big addition to the Galaxy S25 — here’s why
Apple Watch Series 10
Future Apple Watch models could get a surprising new feature — what we know
NYTimes Connections
NYT Connections today hints and answers — Monday, March 24 (#652)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #386 (Monday, March 24 2025)
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less