WhereIsAtlas · Technology
What Happened to AdultFriendFinder?
A 2016 breach reported at 412 million accounts, a parent company that filed for Chapter 11 and sold Penthouse — and a website that is still running.
AdultFriendFinder is an adult dating and social networking website launched in 1996 and owned by FriendFinder Networks. On 13 November 2016 a database of 412 million accounts was reported leaked from the group's websites, more than 339 million of them AdultFriendFinder accounts, with passwords stored in plain text or in unsalted SHA-1. The parent company had already filed for Chapter 11 bankruptcy in 2013 and sold the Penthouse brand in 2016. The site still operates, and founder Andrew Conru regained majority control in 2021.
The business, not the subject
AdultFriendFinder is an adult dating and social networking website. It began in 1996 as a spin-off of FriendFinder.com, an early social networking service started by Andrew Conru after he sold the online dating site he built in the early 1990s. The operating company, Various, Inc., was based in Sunnyvale, California [1][2].
That is the whole of what needs saying about the product. The reason the site belongs in a registry of what happened to things is corporate: a leveraged buyout, a failed listing, a bankruptcy, a magazine brand sold off, and two data breaches — the second of which was, on the figures reported at the time, the largest of 2016.
December 2007: Penthouse buys the company
In December 2007 the owners of Penthouse magazine bought Various, Inc. for $500 million, and the enlarged group later took the name FriendFinder Networks [1][2].
The deal loaded a membership business with acquisition debt. In 2008 FriendFinder filed for a $460 million initial public offering, most of the proceeds earmarked to pay down $420.1 million in short-term debt and other obligations. The listing was delayed and then, in February 2010, shelved indefinitely. As of January 2010 the company reported a negative net worth of $118 million, $32 million in cash and $650 million in liabilities [1].
In 2010 it made a $210 million bid for Playboy Enterprises. Hugh Hefner, who controlled 70 per cent of the voting stock, did not want to sell, and the bid failed [1].
Two bankruptcies, and which was whose
This is the part of the story that is most often blurred, so it is worth separating carefully.
FriendFinder Networks filed for Chapter 11 bankruptcy protection in September 2013, having been delisted from NASDAQ in August 2013 because its stock had not traded above $1. The company had not turned a net profit since at least 2008. Its chief financial officer, Ezra Shashoua, blamed lower revenue on falling membership, higher advertising costs for affiliates, and credit card companies refusing to process transactions for the company's internet businesses. A deal with noteholders cut debt by about $300 million, and in December 2013 a US Bankruptcy Court in Delaware approved the reorganisation, with founder Andrew Conru emerging as chairman and chief executive [1][2][9].
Penthouse Global Media is the second one, and it was a different company. FriendFinder Networks sold the Penthouse brand to Penthouse Global Media — a new company formed by the brand's managing director, Kelly Holland — in February 2016 [1]. That buyer filed for bankruptcy protection in January 2018, a filing Bloomberg described as the third time the magazine's publisher had done so [10].
So the parent company's bankruptcy came first, in 2013, and it survived it. The brand it had bought and then sold went bankrupt later, under new owners.
13 November 2016: 412 million accounts
On 13 November 2016 it was reported that a database of more than 412 million accounts had been breached and leaked from several FriendFinder Networks websites [1][12].
The breakdown reported at the time, based on an analysis by the breach-notification service LeakedSource, put 339,774,493 accounts on AdultFriendFinder.com, 62,668,630 on Cams.com and 7,176,877 on Penthouse.com, with smaller numbers from other brands in the group. More than 15 million of the accounts involved had supposedly been deleted [1][2][3].
The totals differ by outlet, and that is worth stating rather than smoothing over: the BBC reported "up to 400 million" accounts [4], The Verge headlined the AdultFriendFinder figure at over 300 million [5], and Wired put the Adult Friend Finder number at 339 million [6]. The 412 million figure is the group-wide total including the sister sites [3][12].
The data included usernames, email addresses, passwords, membership details, the IP address of the last login and the date of the last visit. Passwords were either stored in plain text or hashed with the obsolete SHA-1 algorithm without a salt — LeakedSource said it had cracked 99 per cent of them. The same analysis claimed 5,650 addresses ending in .gov and 78,301 ending in .mil were caught up in it [1][2][3].
The breach was reported as the second in two years for the same group: in May 2015 attackers had taken data on roughly four million AdultFriendFinder users [2][3].
Coverage at the time attributed the intrusion to exploitation of a local file inclusion flaw, first reported by a researcher using the name Revolver, who denied involvement in the attack itself; who was behind it was not established publicly [3].
What the breach said about the security
The 2016 leak was not a sophisticated attack against a hardened target. Unsalted SHA-1 hashing has been considered inadequate for password storage for well over a decade; storing passwords in plain text is worse. Deleted accounts that were still sitting in the database — over 15 million of them — meant users who had asked to be removed were exposed anyway [1][2][3].
That last detail echoes the finding in the Ashley Madison case, where regulators said the company had sold a "Full Delete" service it did not carry out in all instances: a service that sold its members a form of privacy, and then could not deliver it.
The company's public response has been described in later coverage as a substantial change of practice — moving to salted hashing, bringing in outside security firms, and forcing periodic password resets. That account comes from a commercial review of the product rather than from a filing, and it is the company's own position [11].
The regulator case came before the breach, not after
The one documented enforcement action against the business is not about the 2016 hack at all. In December 2007 the US Federal Trade Commission brought charges against Various, Inc., trading as AdultFriendFinder, AdultFriendFinder.com and Cams.com, over the way the site advertised [7][8].
According to the FTC, the operation and its affiliates used graphic pop-up advertisements that were displayed to consumers who had searched online for ordinary terms such as "flowers", "travel" and "vacations", exposing consumers, including children, to imagery they had not asked to see; in some cases the ads were distributed using spyware and adware. The commission charged that displaying graphic pop-up ads without consumer consent was unfair and violated the FTC Act [7][8].
The settlement required the defendant to stop showing adult pop-up ads unless consumers were actively seeking such content or had consented to it, to take steps to ensure affiliates complied and to end relationships with those that did not, to set up a mechanism for consumer complaints, and to keep records so the commission could monitor compliance. It stated that it did not constitute an admission of a law violation, and the complaint was filed in the US District Court for the Northern District of California [7][8].
No public enforcement action arising from the 2016 breach appears in the sources reviewed for this entry. The pattern is the opposite of Ashley Madison's, where the hack and the regulator's findings arrived together [1][3][12].
Where the website is now
AdultFriendFinder is still operating. FriendFinder Networks continued to trade after the 2016 disclosure, and the site is still written about as a working product in 2026 [1][2][11].
The company changed hands along the way. In 2021 founder Andrew Conru reacquired majority control through a debt acquisition, returning to a business he had sold in 2007; Brock Purpura was appointed chief executive in August 2024. The company describes its current approach as a "people-first platform" [1].
So the short answer to what happened to AdultFriendFinder is that the company nearly died and the website did not. FriendFinder Networks went into Chapter 11 in 2013 and came out of it; the Penthouse brand it had bought for $500 million was sold in 2016 and its buyer was bankrupt by 2018; and the site itself, breached twice and named in the largest reported leak of 2016, is still online a decade later, run again by the man who started it.
Entries in this story
Sources
- Friend Finder Networks — Wikipedia (2026-09-19) ↩
- Adult FriendFinder — Wikipedia (2026-09-19) ↩
- AdultFriendFinder company data breach exposes 412 million accounts — Security Affairs (2026-09-19) ↩
- Up to 400 million accounts in Adult Friend Finder breach — BBC News (2026-09-19) ↩
- Over 300 million AdultFriendFinder accounts have been exposed in a massive breach — The Verge (2026-09-19) ↩
- 339 million Adult Friend Finder accounts exposed in data breach — Wired (2026-09-19) ↩
- Adult-Oriented Online Social Networking Operation Settles FTC Charges; Unwitting Consumers Pelted With Sexually Graphic Pop-Ups — Federal Trade Commission (2026-09-19) ↩
- AdultFriendFinder rapped for X-rated pop-ups — The Register (2026-09-19) ↩
- Penthouse publisher FriendFinder files for bankruptcy — Reuters (2026-09-19) ↩
- Penthouse Magazine Publisher Files Bankruptcy a Third Time — Bloomberg (2026-09-19) ↩
- 3 AdultFriendFinder security improvements made after the 2016 data breach — Mashable (2026-09-19) ↩
- More than 412 million adult-website credentials hacked — CBC News (2026-09-19) ↩