• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechAshley Madison

Hackers have cracked more than 11 million Ashley Madison passwords

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
September 11, 2015, 12:19 PM ET
Homepage of Ashley Madison website displayed on iPad, in photo illustration taken in Ottawa
The homepage of the Ashley Madison website is displayed on an iPad, in this photo illustration taken in Ottawa, Canada July 21, 2015. Canada's prim capital is suddenly focused more on the state of people's affairs than the affairs of the state. One in five Ottawa residents allegedly subscribed to adulterers' website Ashley Madison, making one of the world's coldest capitals among the hottest for extra-marital hookups - and the most vulnerable to a breach of privacy after hackers targeted the site. REUTERS/Chris Wattie - RTX1L9H3Photograph by Chris Wattie — Reuters

After hackers leaked Ashley Madison data in three massive dumps, security experts discovered a commendable surprise within the infidelity site’s source code. Ashley Madison‘s programmers had, it seemed, protected users’ passwords with strong cryptography. Given the time and computing power needed to crack the whole lot, some researchers believed deciphering it might take centuries.

Turns out that wasn’t the whole story. A group of hobbyist hackers revealed in a blog post on Thursday that it has cracked more than 11 million of the some 36 million credentials registered to the site. The team, which calls itself “CynoSure Prime,” was able to decode them by exploiting fatal flaws in the developers’ implementation of a password obfuscation technique known as hashing.

To be technical, the programmers had used a hashing algorithm called “bcrypt,” which makes information so encoded extraordinarily difficult to crack. The cipher is designed to hinder hacking attempts like a ballistic vest blocking bullet rounds.

“We wondered if it had always been this way,” the Cynosure team wrote in its blog post, describing what prompted the group to dig through thousands of lines of source code to find out.

Having inspected the computer instructions, the team uncovered several critical weaknesses. One of the worst of them: More than 15 million Ashley Madison passwords had originally been secured with a different hashing algorithm, MD5, which is more of a quick-and-dirty crypto-procedure than a true safeguard. That gave the group an entry point.

“[T]his line was changed on 2012-06-14,” the team wrote of the switch from the MD5 to the bcrypt algorithm on June 14, 2012. “This meant that we could crack accounts created prior to this date.”

Cynosure told Coins2Day that it has verifiably cracked 11,542,930 of the passwords so far—”using the discoveries we have made AND also other methods which have not talked about yet”—and has 3,720,051 tokens left to go. Less than 5 million of the cracked passwords are unique, according to the team. That means roughly 2-in-5 of them are repeats.

“These numbers are constantly in flux as we have more cracks coming in waiting in the validation queue,” the team wrote to Coins2Day in an email. “We will be releasing a package to the press containing all the statistics for them to discuss in their articles soon.”

Although the team has chosen for the moment not to release the decrypted passwords, it has walked through its methodology in the aforementioned blog post, letting anyone with the know-how to follow suit and replicate the results. You can read more about the team’s methods here.

For more on Ashley Madison, watch this video below.

Subscribe to Data Sheet, Coins2Day’s daily tech and business newsletter.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.