Ashley Madison hackers: we still have 300GB of employee emails, internal docs, some user chats and pictures, more, but will not dump all of it
Ashley Madison Hackers Speak Out: ‘Nobody Was Watching’ — For the past week, international media has reported on the hack of extramarital site Ashley Madison …
Context & Ripple Effects
A month after the original breach disclosure, Ashley Madison is in a rolling leak rather than a single dump: a 9.7GB trove hit the dark web on August 19 with emails, profiles and card transactions, followed by a new 20GB archive of company emails two days later that internal documents confirmed as real.
Today's statement changes the shape of the crisis: the hackers claim to hold roughly 300GB more — employee email, internal docs, some user chats and pictures — and are explicitly declining to publish all of it, keeping the remaining corpus as open leverage over the company and its users.
First-order effects
- Ashley Madison cannot treat the breach as contained: with 300GB of employee emails and internal documents still in attackers' hands, every corporate communication remains exposed to future release regardless of what the company does next.
- Users whose chats and pictures sit in the withheld portion stay in indefinite limbo — their exposure is no longer a one-time dump but a standing threat the hackers control.
Second-order effects
- Selective retention turns the leak into an ongoing news cycle rather than a spike, forcing Ashley Madison to defend against both published data and the possibility of more, while the already-released material keeps compounding damage — over 11 million passwords have since been cracked from the dumps.
- The withheld employee email is the highest-risk asset for the company itself: internal documents already surfaced in earlier archives exposed practices like fake 'fembot' accounts, and further email releases would hand regulators and plaintiffs ready-made evidence.
Third-order effects
- If the probe findings hold — that Ashley Madison violated privacy laws and concealed bot accounts from investigators — the breach becomes a template for how leaked internal records, not just user data, drive regulatory action and forced compliance agreements.
- The pattern points toward extortion-by-retention as a structural feature of large breaches: attackers who hold data back keep pricing power over the victim indefinitely, pressuring companies and regulators to treat a breach as unresolved until the stolen corpus's fate is settled.
The trend: Large-scale breaches are evolving from one-time data dumps into prolonged standoffs where attackers meter out stolen corporate records to sustain leverage.