KONCYBER

The Breach Debrief

Breach Debrief: The Ashley Madison Breach Nobody Was Ever Charged For

August 21, 2026

This is the second entry in The Breach Debrief. I take a real, publicly documented cyber breach, walk the chain of events the way an investigator would, and pull out the lessons - some obvious, some not. This one is personal: I was working cybercrime investigations with Toronto Police Service at the time, so some of what follows comes from having lived it, not just researched it.

Next up: Ashley Madison.

What happened

Ashley Madison was a commercial dating website built around a blunt pitch: discreet extramarital affairs. It launched in 2002 under Avid Life Media, founded by Noel Biderman, and by 2015 had tens of millions of registered users worldwide.

On July 15, 2015, a group calling itself Impact Team announced it had broken into Avid Life Media's servers. Their stated motive wasn't money. They accused the company of dishonest business practices - specifically, charging users a $19 fee for a "full delete" of their personal data that the company didn't actually perform - and gave Avid Life Media an ultimatum: shut down Ashley Madison and its sister site permanently, or they'd release everything.

Avid Life Media didn't comply. On July 20, the company published a statement claiming the incident had been contained and user data secured. Impact Team's answer came about a month later: on August 18, close to 10 gigabytes of user data - names, addresses, search history, partial credit card records - hit the dark web, covering more than 30 million accounts. Two days after that, a second dump followed: nearly 20 gigabytes of internal company data, including the CEO's own emails and the site's source code. Their message was short: "Time's up."

The chain of events, as far as it's known

Intrusion: sometime before July 15, 2015 - the exact entry date was never made public. Ultimatum: July 15. Company's public reassurance: July 20. First data dump: August 18. Second data dump: August 20. Investigation: led by the Toronto Police Service, working alongside the FBI, the U.S. Department of Homeland Security, the RCMP, and the OPP, given how many victims and how much infrastructure crossed the Canada-U.S. border.

What's known about how they got in traces back to one detail Impact Team gave a reporter afterward: the network was segmented, which should have contained the damage, but a single reused credential - "Pass1234" - let them VPN in from the open internet and get root access on every server behind it. Segmentation only works if what's inside it isn't all unlocked with the same key.

What's still not known, more than a decade later: who did it. No arrests. No charges. Impact Team took real precautions - they operated over Tor and left almost nothing forensically usable behind - but "sophisticated" is doing a lot of work in that sentence. A shared root password doesn't require sophistication to exploit. It requires opportunity, and Ashley Madison handed them plenty.

I want to pause on that gap - the one between "the investigation is ongoing" and an actual arrest - because I watched it from the inside, and it isn't really about this one case.

When this file crossed our desks at Toronto Police Service, one thing stuck with me that had nothing to do with Impact Team's tradecraft: how long it took, structurally, to get a dedicated cybercrime unit formally engaged on an investigation of this size. That's not a criticism of any one person or agency - it's a description of how cybercrime investigations were built at the time, and in a lot of places still are: to escalate, not to move at the speed the crime itself happens at. That gap is never neutral. Evidence has a shelf life. Financial trails go cold. Every hour an investigator doesn't have the file yet is an hour the person on the other end gets to spend covering their tracks.

That's not unique to policing, either. It shows up just as clearly in how effectively stolen money gets recovered.

Source: FBI Internet Crime Complaint Center (IC3) 2025 Annual Report; KSL.com, July 2026.

That's a different case and a different decade, but the pattern is the one I saw in 2015: speed isn't a nice-to-have layered on top of a good investigation. It's structural to whether the investigation can succeed at all.

Nobody was ever charged

Given how many resources went into this - four law-enforcement agencies across two countries, years of investigative effort - it's worth sitting with the fact that nobody has ever been arrested or charged for the Ashley Madison breach. Criminal lawyers speculated at the time about what charges could apply if someone were caught: theft, mischief to property, mischief in relation to computer data, extortion, criminal harassment, intimidation. None of it mattered, because there was never a defendant to charge.

Lessons, obvious and not

The obvious one: a segmented network isn't a security program if one password unlocks the whole thing. Ashley Madison's team understood the value of segmentation in theory. In practice, "Pass1234" made it irrelevant. Layered security only works when every layer actually holds.

Second, less obvious: "deleted" is a promise, not a fact, unless you can prove it. Ashley Madison charged users money to delete their data and, according to what came out afterward, didn't fully do it. Computers don't erase data on command - they mark space as available and leave the underlying content until something overwrites it. If your business tells customers their data is gone, that claim needs to be true at the disk level, not just the interface level, because a breach will expose the gap between the two.

Third: motive isn't a reliable predictor of danger. Impact Team wasn't chasing a payout, and everything about how they operated backs that up. Investigators and executives both tend to reach for financial motive as the default lens on a cyber incident, and that's worth resisting here - a moral or ideological motive doesn't make an actor less capable of doing damage. In some ways it makes them harder to negotiate with, because there's no number that makes the problem go away.

Fourth, and the one I think about most: a breach doesn't have a clean end date. Ashley Madison's data has been out for over a decade, and to this day, people connected to it still get targeted - not by Impact Team, but by unrelated opportunists running extortion attempts off the back of a decade-old leak, demanding a few hundred to a couple thousand dollars to keep it from a victim's family. The corporation's incident ended years ago. The exposure for the people in that data never really did.

The takeaway

The technical failure here was almost embarrassingly simple - one reused password undid whatever segmentation existed. The investigative failure is the harder one to sit with: one of the most resourced, most cross-border cybercrime investigations of its era, and it still hasn't produced an arrest. I don't think that's a story about Impact Team being unbeatable. I think it's a story about how much head start speed buys an attacker, and how much of that head start gets built in before an investigator even opens the file. Fix the password problem. But fix the speed problem too - because by the time most cybercrime investigations formally start, the version of the case you're investigating is already the second or third version of what actually happened.

Get the next issue