Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - 400 Million Adult Friend Finder Accounts Breached
News & Analysis

400 Million Adult Friend Finder Accounts Breached

ISBuzz TeamBy ISBuzz TeamNovember 15, 2016Updated:July 8, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Military Intel Leak Investigated by US Officials
Military Intel Leak Investigated by US Officials
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Friend Finder Network Inc was hacked in October of 2016 for over 400 million accounts representing 20 years of customer data which makes it by far the largest breach we have ever seen — MySpace gets 2nd place at 360 million. This event also marks the second time Friend Finder has been breached in two years, the first being around May of 2015. IT security experts from Redscan, AlienVault, ESET, Comparitech.com, Synopsis and Watchful Software have commented below.

Robert Page, Lead Penetration Tester at Redscan:

“Unfortunately many businesses simply do not learn their lesson and by failing to implement proper cyber security controls repeatedly place the privacy of users at risk.  By storing passwords in clear text or insecure formats, companies render even complex passwords useless.  Good user account practice should therefore involve use of unique passwords between websites.”

Javvad Malik, Security Advocate at AlienVault:

Javvad Malik“I’m still getting my head around the extent of the Adult Friend Finder hack. But for all intents and purposes, it looks as if security wasn’t even an afterthought. Not only were passwords stored with trivial protection, but accounts that users had deleted, appeared to not have been deleted at all.

The impact from sites such as Adult Friend Finder could be as significant as the Ashley Madison breach which had reports of suicides as a direct result of the breaches. Whilst probably not at the same level, the Adult Friend Finder breach data does contain several thousand .gov and .mil email addresses.

In a word, it looks like Adult Friend Finder had as close to no security as you can get while running such a website.”

Mark James, Security Specialist at ESET:

mark-james“This leaked data is astounding. The fact that people are still using the most common passwords we see time and again is truly amazing. We know these passwords are out there, we know they are easily cracked, we know we should not be using them but we still do, it makes no sense. Companies need to start putting in measures to stop these passwords being used. We have the lists, they have the lists, it’s a simple lookup. Whilst I appreciate it’s our responsibility to protect our data there are some seemingly easy measures that could be put in place to stop the use of these extremely common words. Some websites already do this but more need to step up and help those people who still do not understand the need for password sense.

With the previous attacks we have seen on these types of websites you would have expected the password storage security to have been increased but sadly this is not the case here. The methods used were considered poor practise by some and terrible by others. Companies need to step up and take control of how they store and manage our data. Yes it’s our job to be responsible but on the same note they should encourage high standards and do more than the required basics to keep it safe.”

Lee Munson, Security Researcher for Comparitech.com:

Lee Munson“The Adult Friend Finder hack, like many that have gone before it, and many that will come after, highlights the poor approach to security taken by even the biggest sites on the web.

The use of SHA1 – whose effectiveness has been questioned since at least 2005 – is almost as disturbing as the fact that over 15 million deleted user account emails were still allegedly kept in the site’s database.

That over 100 million passwords were apparently stored in plaintext is, frankly, ridiculous. If true, the mastermind behind that idea should probably be feeling very uneasy about their future job prospects right now.

Worse, however, is the choice of passwords seemingly picked by those who signed up for an account. Classics such as “123456” and “password” have been flagged up time and again after other sites have been breached.

Both internet users and the security industry as a whole need to get their respective acts together on this in order to prevent the still very widespread and repetitive use of extremely poor credentials.”

Adam Brown, Manager, Security Solutions at Synopsys:

adam-brown“When data breaches occur you want to be sure that the data that is extracted is encrypted to such a level that it is of no use to outsiders.

In this case verification has shown that some data is stored in clear text while passwords are encrypted with SHA-1 (not enough to thwart today’s adversaries).

Unfortunately penetration testing or application security scanning can offer almost no insight into how data is stored or processed inside an organisations applications and data stores.

A data centric approach is needed. It enables organisations to see how their data is managed by systems and more importantly whether it is encrypted and whether that encryption level is satisfactory.”

Justine Cross, Regional Director at Watchful Software:

  “The public has long since run out of patience for companies that fail to protect their data, and the Friendfinder Network is just the latest example proving that businesses must take a new stance to keep information in their care safe.

It is no longer enough to focus on passwords and financial data – any level of breach can cause significant distress or financial harm to the affected customers. Stolen email addresses will leave the victims vulnerable to phishing attacks and fraud across other sites using the address, while names and other details can be used as a source of embarrassment or blackmail.

While companies obviously need to harden their defences against intrusion as much as possible, they must also prepare their data for the event of a successful attack. All data pertaining to customers should be automatically classified and encrypted the moment it is created, ensuring that only authorised users can open it. With this in place, even if data is stolen it will be much more difficult for criminals to make use of it.

Aside from the inevitable legal and reputational backlash, it’s also worth noting that the Friendfinder Network breach would certainly be subject to the upcoming EU GDPR and the huge potential fines it can levy.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

AppSec is dead, long live AI security

April 29, 20265 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}