The dating app that doxxed 72,000 women...

Quick Overview

A data breach exposed over 72,000 selfies and driver's licenses from the dating app "Tea," with the data being uploaded to a public Firebase storage bucket and later leaked on 4chan, leading to the creation of a website that ranks users based on their appearance.

Key Points: The dating app "Tea" suffered a major data breach, exposing approximately 72,000 images, including 13,000 selfies and photo IDs submitted for age verification. This sensitive data was stored in a public Firebase storage bucket, making it accessible to anyone who found the link. The compromised data was leaked on 4chan, leading to the creation of a website that ranks "Tea" users based on their appearance, with some data even being used to create AI girlfriend chatbots. The breach occurred due to a legacy data storage system that was not properly secured, allowing unauthorized access. The app's privacy policy stated that selfies would be deleted after verification, but this was not followed. The founder of "Tea," Sean Cook, has a background in software engineering and previously worked on dating safety tools.

Context: The "Tea" app was designed as a dating safety tool for women, allowing them to share information and gossip about men they've dated. To verify users are women, the app required them to upload a selfie with their ID. This video details a significant data breach that compromised this sensitive user information.

Detailed Analysis

The dating app "Tea," which aimed to provide dating safety tools for women, experienced a massive data breach. The breach exposed over 72,000 images, including approximately 13,000 selfies and driver's licenses submitted by users for age and gender verification. This data was stored in an unsecured public Firebase storage bucket, allowing it to be easily accessed and downloaded. The breach was discovered on July 25, 2025, and the compromised data was subsequently leaked on 4chan. This led to the creation of a website that ranks "Tea" users based on their perceived attractiveness, and some of the leaked data was even used to create AI girlfriend chatbots. The app's privacy policy was misleading, as it claimed to delete user selfies after verification, which was not the case. The vulnerability stemmed from a legacy data storage system that lacked proper security measures. The founder, Sean Cook, has a background in software engineering and previously worked on similar safety-focused applications.

Raw markdown version of this recap