WhereIsAtlas · Technology

What Happened to Ashley Madison?

In 2015 a hack exposed 36 million users of an adultery website. The regulators then found the company had faked profiles and sold a "Full Delete" that did not always work. It is still running.

Ashley Madison launched in 2001 as a dating site for people seeking affairs. In July 2015 a group called the Impact Team breached it, and profile information belonging to 36 million users was exposed. In December 2016 the FTC, the District of Columbia and 13 states settled with its owner for $1,657,000 — a figure that could rise to $17.5 million — over thousands of fake profiles and a "Full Delete" service that was not always carried out. The site still operates, and rebranded in February 2026 to sell "discreet dating" instead of affairs.

The business model was the story

Ashley Madison launched in 2001 and sold one thing: secrecy for people having affairs. The tagline was "Life is short. Have an affair." Its parent was Avid Life Media, later renamed Ruby Corp [8].

That is worth stating plainly at the top, because the events of 2015 are usually told as a lurid hacking story. The more interesting version is a corporate one. The company's product was discretion, and the thing that destroyed its reputation was a failure to provide exactly that.

July 2015: the Impact Team

In July 2015 a group calling itself the Impact Team breached the company and threatened to publish what it had taken unless the site was shut down. It released the details of 2,500 users as proof, and demanded the site close [4][8].

The site did not close. In August 2015 the group published a further 60 gigabytes of data, including records of users who had paid Ashley Madison to remove their information after the first leak — which is itself the detail that matters most, because it meant the people who had tried hardest to protect themselves were exposed by the attempt [4][8].

The FTC later put the number of affected users at 36 million [2].

What a breach like that actually costs people

The leaked information was personal in a way that is hard to overstate: usernames, email addresses, photographs, communications and other profile data, published permanently [1].

The fallout was not abstract. Email addresses were checked against corporate and government systems, and the human consequences — marriages, jobs, and in some cases lives — were reported widely. This is the part of the story that is genuinely a privacy catastrophe rather than an embarrassment, and it is why the case is studied [1][8].

At the end of August 2015, chief executive Noel Biderman stepped down [5][6].

The part that became a regulatory case

The hack alone would not have produced a settlement. What did was what regulators found when they looked at how the company had operated.

In December 2016 the District of Columbia, 13 states and the FTC announced a consumer-protection settlement with ruby Corp., ruby Life, Inc. and ADL Media, Inc. The allegations were specific [1]:

- The company failed to take reasonable steps to secure users' personal information. - It created thousands of fake user profiles. - It misrepresented the strength of its security. - It sold a "Full Delete" option that it did not carry out in all instances.

The fake profiles and the "Full Delete" are the two details that reframe the entire story. A site whose value proposition was that it protected your secret had been padding its numbers with users who did not exist and charging people for a deletion service that did not always delete them [1].

The penalty

The settlement imposed a penalty of $1,657,000, which could rise to as much as $17.5 million depending on a review of the company's financial records [1]. The company also agreed to stop the deceptive practices, to refrain from creating fake profiles, and to implement a stronger data security program [1].

Alongside the District of Columbia, the participating states were Alaska, Arkansas, Hawaii, Louisiana, Maryland, Mississippi, North Dakota, Nebraska, New York, Oregon, Rhode Island, Tennessee and Vermont [1]. The case was significant enough that the FTC's investigation picked up an international award the following year [3].

The site did not die

This is the outcome most people do not expect: Ashley Madison never shut down. It kept operating through the settlement, the rebrand of its parent to Ruby Corp, and the years afterwards [1][8].

On 24 February 2026 the company announced it was dropping the affair framing altogether in favour of "discreet dating," with a new tagline, "Where Desire Meets Discretion." It said internal signup data showed 57 per cent of new members in 2025 identified as single. Paul Keable, the chief strategy officer, framed the pitch as "ethical discretion" for members who are single, separated, divorced or non-monogamous [4].

That is a company trying to sell privacy again — to a customer base it says has changed, fifteen years after the breach that made its name a warning.

What it is a case study in

Ashley Madison is the clearest example in the registry of a specific modern failure: a company that sold trust as its product and was found to have broken it twice — once by losing the data, and once by charging customers for a deletion that did not reliably happen.

The hack was a crime committed against the company and its users. The settlement was about what the company did to its own customers. Keeping those two things separate is the whole point of the case, and it is the reason the site's 2026 rebrand is a harder sell than a new tagline suggests.

Entries in this story

Sources

  1. Owners of Ashley Madison Enter Into Settlement with District, Other States, and FTC Concerning Data Breach — Office of the Attorney General for the District of Columbia (2026-09-19) ↩
  2. Operators of AshleyMadison.com Settle FTC, State Charges Resulting From 2015 Data Breach that Exposed 36 Million Users' Profile Information — Federal Trade Commission (2026-09-19) ↩
  3. FTC Earns Prestigious International Award for AshleyMadison.com Data Breach Investigation — Federal Trade Commission (2026-09-19) ↩
  4. Ashley Madison is rebranding from 'affairs' to 'discreet dating' — USA TODAY (2026-09-19) ↩
  5. Ashley Madison boss steps down after data breach — ABC News (Australia) (2026-09-19) ↩
  6. Ashley Madison CEO steps down following hacking — RTÉ (2026-09-19) ↩
  7. Ashley Madison agrees to $1.7 million settlement — CNN Business (2026-09-19)
  8. Ashley Madison — Wikipedia (2026-09-19) ↩