Privacy watchdogs: Ashley Madison's security was 'unacceptable'

Its security was no good, but you knew that already.
 By 
Ariel Bogle
 on 
Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

The online security of notorious cheating website Ashley Madison had "unacceptable shortcomings."

That fact must have been bitterly obvious to any of its users who had their names, emails and banking details leaked online in mid-2015. It's also the final judgment of a joint investigation between the Australian Privacy Commissioner and the Privacy Commissioner of Canada, the results of which were published Wednesday.

Owned by Avid Life Media (ALM), the site's troubles began in July 2015 when a hacking group called The Impact Team threatened to leak user details unless the company shut down two of its adult dating sites, Established Men and Ashley Madison.


You May Also Like

Not long after, up to 36 million Ashley Madison user accounts were dumped online. Many of those accounts were later determined to be fem-bots set up by the company to interact with male users; a practice the company has said it no longer indulges in.

The privacy commissioners of both countries began their joint investigation in August 2015, focusing on the security safeguards put in place by ALM, now renamed as Ruby Corp.

Of particular concern were four questionable practices: The retaining of personal data after a user had deleted their account, the company's policy of charging for what it called a "full delete," its failure to confirm email addresses and its lack of transparency about how it handled user data.

The report found ALM had failed to put in place an "explicit risk management process," and had also failed to properly train staff about their privacy obligations.

"While ALM fell well short of the requirements we would expect for an organisation managing personal information, breaches can occur in the best run companies," Australian Privacy Commissioner Timothy Pilgrim said in a statement.

Ruby Corp has offered court-enforceable commitments to both commissioners that it will improve its security practices. "The company continues to make significant, ongoing investments in privacy and security," Ruby Corp CEO Rob Segal said in a statement. It is now offering free account deletion to users, among other changes.

Let's hope the security updates are sufficient, because Ashley Madison is now trying to woo back customers.

"The recommendations are all very good, the problem is that it's all happened far too late and far too much damage has been done.

According to Mark Gregory, privacy expert and senior lecturer at Melbourne's RMIT University, the report highlights the need for mandatory data breach laws to be passed in Australia.

"The recommendations are all very good, the problem is that it's all happened far too late and far too much damage has been done," he told Mashable Australia.

In his view, such laws would force companies to improve their security systems, for fear of falling afoul of a requirement to mandatorily contact people and tell them what had happened.

Australian companies do not have a clean slate when it comes to the leaking of personal customer details online. In 2015, Kmart and David Jones suffered data breaches, among others.

In 2015, the government released a draft of a data breach notification bill, but its progress through parliament has stalled. The government "remains committed" to introducing the mandatory data breach notification legislation, an Attorney-General's Department spokesperson told Mashable Australia.

Gregory said the government is letting down consumers by not passing the legislation and putting the onus on the industry to improve their security practices.

"The lack of mandatory data breach reporting legislation, the lack of legislated penalties for failing to comply with reasonable privacy requirements -- it makes you wonder, what onus would there be for a company like Ashley Madison to do anything recommended in the report in Australia?

UPDATE: Aug. 25, 2016, 2:19 p.m. AEST Attorney-General's Department statement added.

Mashable Image
Ariel Bogle

Ariel Bogle was an associate editor with Mashable in Australia covering technology. Previously, Ariel was associate editor at Future Tense in Washington DC, an editorial initiative between Slate and New America.

Mashable Potato

Recommended For You
Adultery app Ashley Madison says it's rebranding to 'discreet dating'
Ashley Madison homepage

Trump's new White House app is a security and privacy nightmare
President Donald Trump at the White House

See Samsung Galaxy S26's Privacy Display feature in action
galaxy s25 ultra phone on display at galaxy unpacked launch event

Updating your security mindset: Keep your data private and your devices secure
By PCMag
Cyber Security


Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.

Wordle today: Answer, hints for April 4, 2026
Wordle game on a smartphone
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!