Once seen as bulletproof, 11 million+ Ashley Madison passwords already cracked
Programming errors make 15.26 million accounts orders of magnitude faster to crack. — When the Ashley Madison hackers leaked close to 100 gigabytes worth of sensitive documents belonging to the online dating service …
Context & Ripple Effects
The initial July hack of Ashley Madison's 37M-user database escalated through August as hackers posted a 9.7GB dump on the dark web and then a 20GB archive of company emails and internal documents, with multiple sources confirming their own data was genuine despite former-CTO denials.
Today's development is about what happens to that leaked data over time: programming errors in how 15.26 million accounts were hashed have made them orders of magnitude faster to crack, and more than 11 million passwords are already broken — turning a static dump into an escalating exposure for users who assumed hashed meant safe.
First-order effects
- Millions of current and former Ashley Madison users whose credentials relied on the flawed hashing now face direct account compromise, since attackers can test recovered passwords against email addresses in the dump.
- Ashley Madison's technical credibility takes another hit after its former CTO publicly disputed the data's authenticity — a claim undercut by independent confirmations of real user records.
Second-order effects
- The company's C$500,000 bounty for identifying the hackers gains urgency as each newly cracked batch of passwords deepens legal and regulatory exposure, including the ongoing joint Canada-Australia privacy probe.
- Credential-cracking tools built for this dump spill beyond the dating site itself, because reused passwords expose users' accounts at email providers, employers, and financial services.
Third-order effects
- If hashing errors of this kind prove common across consumer services, regulators and plaintiffs' bars gain a template for treating weak credential storage as negligence rather than bad luck, raising the compliance floor for any site holding sensitive behavioral data.
- Breach liability shifts from the moment of theft to the years-long tail of decryption — companies may need to plan disclosures and remediation around how long their stored secrets actually resist attack.
The trend: Data breaches are becoming slow-motion events where weak cryptography, not the initial theft, determines how much lasting harm leaked databases inflict on users.