# The 'Tea App' Hack Takes an Insane Turn

Source: https://www.youtube.com/watch?v=wg0z_TflQ7c
Recap page: https://rapidrecap.app/video/wg0z_TflQ7c
Generated: 2025-08-12T16:04:19.079+00:00

---
## Quick Overview

The 'Tea App' hack escalated with a rival app, 'Tea on Her,' accidentally replicating the original's vulnerability, leading to the exposure of thousands of government IDs, user DMs, and private messages, with lawsuits already filed.

**Key Points:**
- The 'Tea App' suffered a massive data breach, exposing 72,000 images including government IDs and verification selfies to 4chan due to a misconfigured Firebase backend.
- A second breach within the 'Tea App' exposed millions of private messages, with timestamps indicating some were as recent as the previous week.
- A rival app, 'Tea on Her,' designed for men to gossip about women, replicated the original app's vulnerability, exposing user IDs, emails, and selfies.
- Thousands of government IDs were leaked from the 'Tea App' hack.
- Ten women have already filed lawsuits against the 'Tea App' developers following the data breaches.
- Cybercriminals (LightBasin) attempted to hack ATMs using a Raspberry Pi by physically connecting it to a bank's network switch, but their plan was foiled by cybersecurity firm Group IB.

**Context:** The video discusses two major cybersecurity incidents: a data breach affecting the 'Tea App,' a dating safety app for women, and an attempted ATM hack by a group known as LightBasin. The 'Tea App' was targeted by 4chan, leading to the leak of user data. A subsequent rival app, 'Tea on Her,' also experienced a similar breach. The ATM hack involved physical access to a bank's network to deploy a remote access tool.

## Detailed Analysis

The 'Tea App,' designed for women to research dates and gossip, suffered a massive data breach due to a misconfigured Firebase backend, exposing 72,000 images, including government IDs and verification selfies, to 4chan. This breach was followed by a second, more severe leak of millions of private messages, some as recent as the previous week, prompting the app to disable its direct messaging feature. Amidst this drama, a copycat app called 'Tea on Her' emerged, targeting men for similar gossip, but it also inadvertently duplicated the original app's vulnerability, exposing user IDs, emails, and selfies. Separately, cybercriminals attempted to hack ATMs using a Raspberry Pi by physically accessing a bank's network switch, aiming to deploy a rootkit to facilitate fraudulent withdrawals, but their attempt was thwarted by cybersecurity firm Group IB after the device was discovered and disconnected.

### Original Tea App Hack

- Misconfigured Firebase exposed 72,000 images including government IDs and selfies to 4chan
- Second breach leaked millions of private messages, some as recent as last week
- Lawsuits filed against the app developers

### Tea on Her App

- Rival app for men inadvertently duplicated original vulnerability
- Exposed user IDs, emails, and selfies
- Developer ignored researcher's emails and left creator credentials exposed

### ATM Hacking Attempt

- Cybercriminals (UNC2891/LightBasin) attempted to hack ATMs using a Raspberry Pi connected to a bank's network switch
- Plan was to deploy CakeTap rootkit for fraudulent withdrawals
- Attempt failed when Raspberry Pi was discovered and disconnected, with cybersecurity firm Group IB detecting and blocking further access

