
The Ashley Madison -acting work specializes in acquaintances for people in relations who are looking for a couple for cheating. Since the launch, the company guaranteed users complete confidentiality, but after a hacker attack in 2015, the data of almost 40 million people were in the public domain - as it turned out that the company neglected the safety rules for years. Netflix released a documentary about how it became possible and how it influenced the life of users. "Cold" retells the main thing from this story.
In order not to miss the main materials of the "cold", subscribe to our Instagram and telegram .
Ashley Madison-Canadian online dating service for people in marriage. In 2001, it was created by the investor and venture capitalist Darren Morgenstern. The idea to create a site exclusively for married people arose with him when he studied the statistics of ordinary dating sites and realized that 30% of users are married.
By July 2015, the Ashley Madison -acting work, which helped married people find a partner for betrayal, while maintaining anonymity, served 37 million users in 50 countries. The company was going to go to an IPO, waiting for a high price for shares, and planned to attract $ 200 million, estimating its value of a billion dollars.
Everything changed on July 13, 2015.
“I remember how I came to the office. Usually people think about something, drink coffee, chatting. But that day, an oppressive, unnatural silence reigned, ”said Evan Back, Ashley Madison Vice President. -I thought that someone probably got to catch up with the authorities. I turned on the computer, the image appeared on the screen and music began to play. Such slaughter rock and roll. I thought: what is this crap? ”

It was the song of the AC/DC Thunderstruck, which at that time already became a hymn of hacker attacks and which, according to one version, was used by hackers who attacked Iranian nuclear objects. Ashley Madison’s internal system was hacked and the company's leadership was set by an ultimatum .
“We are Impact Team. We took control of all systems in all your offices and premises, the report said. - All databases with information about customers, storage of source codes, financial reports, emails. Disconnecting AM and EM (company sites, Ashley Madison and Establined Men. - Approx. “Cold”) will cost you expensive, but non -compliance with the requirements is even more expensive. We will publish all the records of customers, profiles with all secret sexual fantasies, naked photos, conversations and transactions on credit cards, real names and addresses, as well as documents of employees and emails. Avid Life Media (a company owned by Ashley Madison and Establined Men. - Approx. “Cold”) will be responsible for fraud and causing serious harm to millions of users. ”
Impact Team announced that the companies were giving 30 days to completely stop working all sites. Otherwise, all the data of customers and employees will be in the public domain.
“I went to talk with Noel ( Noel Biderman is the general director of the company. - Approx.“ Cold ”) and higher leadership,” Back recalled. - Everyone was on the platoon, but Noel simply tore the metal. If this gets into the press, a disaster will happen. ”
Avid Life Media's leadership tried in every possible way to hide the information about the hacking and did not contact the police. The company decided to independently find out who exactly made a hack. To do this, Avid Life Media invited European cybersecurity consultants to Toronto.
Experts studied the hackers' message and noticed that Impact Team did not require recognition, money or some other benefits, which means that the attack was motivated ideologically. According to one version, hacking could be made by religious fanatics, offended customers or their spouses.

July 19 , a week after hacking, information about what happened leaked to the media: Impact Team Hackers themselves published on the network a post on the hacking of Ashley Madison. The news was discussed in social networks, on television , and even in evening shows.
From the media, the chief of police Toronto also learned about what happened. According to Canadian laws, such a hack is considered a criminal offense, so the police themselves went to the leadership of Ashley Madison to find out all the circumstances of the attack.
By that time, cybersecurity experts discovered the first clues.
Studying the log files-the recordings of what happened before Ashley Madison servers-they found that hackers connected to the system under the guise of an employee using the software used by the previous contractor of the company (the name is not disclosed) . However, the contractor no longer worked with Ashley Madison when the connection occurred.
The forensics met with the former Ashley Madison contractor in a cafe. He said that he really penetrated the system, but did not recognize participation in the hack. Ashley Madison did not believe him and offered a large amount of money, sufficient so that he could pay a mortgage, provided that no information will be made public. However, the alleged hacker did not recognize his participation, did not give any promises and the deal did not take place.
There was no use from the police either. They did not have enough information to make charges the alleged hacker.
Before the "Dedlin", which the hackers put, there were only a few days left, but dating sites continued to work as if nothing had happened.
On August 19, Impact Team fulfilled their promise and leaked data about Ashley Madison and Establined Men to the network: names, email addresses, banking operations and much more.
The published data quickly began to study both journalists and ordinary users. On the Web, the names of famous bloggers, politicians, stars and their spouses survived every now and then. According to journalists, about 15 thousand male of the American military and civil servants were registered on the site. The Son of the current US President Joe Biden, Hunter Biden, also included the son of AM users, but hedenied his registration of the dating site.
Many users began to receive threat letters. The attackers suggested that the Ashley Madison list pay them to remove their names from the database. However, it is not clear whether these blackmailers were generally somehow connected with Impact Team. The only thing that the victims were advised in the technical support of Ashley Madison is to change the password .
On the TV channels, Ashley Madison was criticized, the service was called a “ugly business” and hoped that he would go bankrupt soon. However, some employees of Ashley Madison believed that there was no bad advertising. "There was an unprecedented increase in site visits," the company said.
The invited forensics began to suspect that the data drainage could be a PR action provoked by the CEO of Noel Biderman. However, they abandoned this version when a few days after the first drain, the hackers uploaded the second array of data into the network. This time, in addition to these users, internal documents, files and tables of the company got into the network. In addition, Biderman himself, including his correspondence, were presented there.

As a company general director, Biderman has repeatedly given an interview on which he appeared with his wife Amanda. Biderman claimed that they have honest and trusting relationships in which there is no need to start novels on the side. At the same time, Amanda repeatedly repeated that her husband’s betrayal would be a blow to her, but she is sure that this would never happen.
However, based on the letters published by Impact Team, it became clear that Noel repeatedly cheated on his wife.
“I'm looking for a young, cheerful, kind woman for meetings once a month,” Biderman wrote in one of the letters.
In addition, it turned out from the leak that the general director of the company often looked for women through the escort agency. At the same time, his services of girls aged 18-19 were interested. He also demanded to send him two girls at once.
After the hackers posted all these data on the network, the company's management suspended their own investigation and decided to cooperate with the police.
On August 24, the Toronto police gathered a press conference at which she announced a reward for information about hackers-500 thousand dollars. It was 10 times more than the police could offer without the participation of the company. However, no one responded to this police request.
Ashley Madison was not known about the Impact Team group. Journalist Joseph Cox, specializing in this topic, could not find out anything about them, including other hackers and journalists. In the hope of finding at least some information, Cox began to explore the forums in the darknet and found a person who was clearly connected with the crackers, as he knew many details about the attack and the hacker group. Cox persuaded him to transmit Impact Team with a request to answer a few questions and soon the hackers contacted him.
In correspondence, they said that they began to work on a hack for a long time, because they did not want to allow even more popularity of the service.
“Avid Life Media as a drug dealer mocking dependent,” the crackers wrote.
According to the representative of Impact Team, the hackers were not surprised that the company continued to work: according to their estimates, Ashley Madison earned $ 100 million a year. At the same time, the main motivation of hackers was that the site deceives customers, so they believed that it needed to be exposed.
To find confirmations of the Impact Team words, Joseph Cox began to study the data published on August 21. As it turned out, Ashley Madison’s leadership thought about security last. The internal correspondence was devoted mainly to PR and sales, but not to protect the data. The site hung various awards for supposedly the most high -quality security system, but they turned out to be a fake drawn in an ordinary photo editor. On the Ashley Madison page there was even an icon of the gold medal “Safety Award”, which the authors of the site, apparently, were handed to themselves.
Users were deceived not only with false achievements. On the Ashley Madison website you could purchase a special service: deleting all the user data from the company's servers for $ 19. It turned out that in fact the company did not remove them.
In addition, one of the main problems of Ashley Madison was the lack of a female audience. To attract women to the community, the company made them completely free access: it was not necessary to pay either for registration or sending messages. The service was paid only for men. They had to buy the so -called loans that could be spent on messages. For $ 49, the user received 100 “loans”. This amount was enough for sending messages to 20 accounts.
According to official figures, the ratio of men and women among users was 60% by 40% in most regions.
But as it turned out later, most of the women with whom the site users communicated never existed. Ashley Madison presented a huge number of fake women's accounts registered with the same IP address-from the company's office.
As the journalists of the IT publication Gizmodo found out , a large number of messages generated bots. They were the first to send messages, and to answer, the men had to pay.
Inside the company, the use of bots was explained by the fact that many men are too shy to send the message first. And none of the users, of course, knew that he was communicating not with a real woman, but with artificial intelligence, who sends 10 thousand messages per day. The text of these messages was specially selected so as to attract men.
From hacking, Ashley Madison was not so much top management as ordinary users.
John, a 56-year-old teacher of the seminary from New Orleans, met his wife Christie in his youth . Before starting to meet, they wrote to each other paper love letters.

“John knew how to write letters beautifully. He was an idealist, and it seemed to me that we had common goals. I turned 24, and we got married. I was full of hopes that a wonderful life was waiting for me, ”recalls Christie.
According to her, although others were sure that they had a very happy relationship, in decades their marriage experienced various difficulties.
Once Christie found love letters that someone sent John. It was especially disappointing for her, because their relationship began with letters.
When Christie first heard about the hacking of Ashley Madison, she immediately thought that she could find her husband’s lists, but did not check so as not to hurt herself.
On August 24, 2015, a few days after the publication, Christie and John woke up, as usual, drank coffee, discussing plans for the evening, and then parted about their business.
When Christie returned home, John was not in the kitchen. She began to look for him around the house, looked into the garage and saw her husband’s body: John killed himself, suffocating with carbon monoxide.
Later it turned out that on that day John was called to talk to the leadership of the seminary. There he was informed that his name was found on the list of users of the Ashley Madison site.
“They told me that he burst into tears and did not even try to deny it. He simply said: “Yes. I know, you want me to quit,” recalls Christie.
John was from a family where there were three generations of pastors. He taught young people who planned to devote their lives to serving God. His reputation was destroyed .
European experts, investigating hacking, came to the conclusion that Impact Team was created specifically to attack Ashley Madison. Nobody heard anything about this team of hackers.
The forensics suspect that an insider, one of the employees of the company, was involved in hacking. They were led to this thought that in their messages, hackers mentioned the names of several high -ranking managers whom they could not know without communicating with them personally.
Toronto police stopped their investigation. The investigative-operational group was disbanded. None of the hackers Impact Team were found.
After the scandal, the general director of Avid Life Media Noel Biderman left the position. Ashley Madison's maternal company has changed its name to Ruby Corp. And paid 11 million dollars to a group of users who filed a collective lawsuit.
According to the company's report for 2020 , Ashley Madison at that time already used 70 million people.