Report: Ashley Madison Data Leak Was an Inside Job

Report: Ashley Madison Data Leak Was an Inside Job

LOS ANGELES — If Internet security expert John McAfee is correct, the much publicized data breach of adult affair site AshleyMadison.com was an inside job.

In an article for International Business Times, John McAfee claims that Ashley Madison was not hacked, but its most private data — including sensitive consumer information — was stolen by a female employee of parent company Avid Life Media, who was working on her own.

McAfee has been analyzing the 40GB data dump, and determined that it was the result of a lone wolf attacker with intimate access to the company’s systems.

“A hacker is someone who uses a combination of high-tech cybertools and social engineering to gain illicit access to someone else’s data,” McAfee wrote. “But this job was done by someone who already had the keys to the Kingdom. It was an inside job.”

“Any adept social engineer would have easily seen this from the wording in the first manifesto published by the alleged hacking group,” McAfee added. “I was one of the first practitioners of social engineering as a hacking technique and today it is my only tool of use, aside from a smartphone — in a purely white hat sort of way.”

In his article, McAfee outlines the processes he used to make his assertions, and discusses the type of information he was able to glean from the data dumps, including the decoded password hash tables of every company employee, MySQL databases, office layouts, organization charts and every private email to and from the CEO — even the raw source code for all the company’s programs.

There was so much information in the breach, garnered from multiple systems, and with so much of it having no value to outside organizations, that it convinced McAfee that the breach was an inside job.

“These are just a few of the many strangely included files that would take even a top notch hacker years to gather, and seem to have little or no value,” McAfee explains. “Any reasonable cybersecurity expert would come to the conclusion that only someone on the inside, who could easily gain all of the files through deception and guile, could have done the job.”

As for those high-level emails, Krebs on Security is reporting that contained within in them are revelations that a former Ashley Madison exec had hacked a competitor’s website — grabbing its full user database.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

FSC Publishes Guidance on Google Analytics Lawsuits

The Free Speech Coalition (FSC) has published guidance on how adult websites can protect themselves in the wake of several consumer class action lawsuits filed against sites for using Google Analytics.

BranditScan, CreatorTraffic Partner for 'Creators & Agencies' Initiative

BranditScan and advertising network CreatorTraffic have partnered for an initiative to help creators and agencies generate traffic and protect their content.

Teasy Agency Joins Pineapple Support as Supporter-Level Sponsor

Teasy Agency has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

Aylo, Pineapple Support Partner for Mental Health Video Series

Aylo has teamed up with Pineapple Support to create a safety video series aimed at educating performers and creators about mental health.

Ofcom Investigates FTV Sites for Possible AV Noncompliance

U.K. media regulator Ofcom is investigating First Time Videos, which operates the sites FTVGirls.com and FTVMilfs.com, for possible failure to comply with age assurance requirements under the Online Safety Act.

Stalwart Defender: Jeffrey Douglas on 30 Years Fighting for Free Expression

“If you had told me in 1995 that I would be on the FSC board for 30 years, I would have laughed out loud,” says Jeffrey Douglas.

FSC Publishes Analysis of Federal Trade Commission Event Promoting AV

Free Speech Coalition (FSC) has published an analysis of a Federal Trade Commission (FTC) event held this week that promoted age verification among other forms of speech regulation.

GirlsDoPorn Owner Michael Pratt Pleads Guilty to Sex Trafficking

Michael Pratt, former owner of the rogue website GirlsDoPorn, pleaded guilty in the U.S. District Court for the Southern District of California on Thursday to sex trafficking and conspiracy to commit sex trafficking charges, according to a report by City News Service.

Master Nico Relaunches Site Through YourPaysitePartner

Master Nico has relaunched his official website through YourPaysitePartner (YPP).

Federal Judge Grants Partial Halt of Florida AV Law

The United States District Court for the Northern District of Florida, Tallahassee Division, has granted a preliminary injunction against HB 3, the state's age verification law, as a lawsuit filed by two online trade associations challenging the law makes its way through the courts.

Show More