Skip to main content
Breach Signal

Breach report

Social Media

Match Group (Hinge, OkCupid, Match.com)

Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match

ShinyHunters breached dating giant Match Group in January 2026 by voice-phishing an employee's Okta login, then leaked what it said were 10 million user records from Hinge, Match and OkCupid, plus internal files.

Reported by BleepingComputer

Records exposed

10M

About 10 million records (claimed)

Scale vs. largest on file

When
2026
How they got in
Voice phishing (vishing) of Okta single sign-on account
Sector
Social Media

In late January 2026, Match Group, the parent company of Tinder, Hinge, Match.com, OkCupid and Meetic, confirmed a security incident after the extortion group ShinyHunters listed it on its data leak site. The hackers claimed to have taken more than 10 million records tied to Hinge, Match and OkCupid, along with hundreds of internal documents, and they published about 1.7 gigabytes of compressed files when the company did not meet their demands.

The attack relied on social engineering rather than a software exploit. According to BleepingComputer, the intruders used voice phishing, calling an employee and directing them to a lookalike domain designed to harvest credentials for Match Group's Okta single sign-on system. Once inside the employee's SSO account, the attackers could reach connected services, including the AppsFlyer marketing analytics platform and cloud storage, where user-level app data and company files were kept.

Match Group said it acted quickly to terminate the unauthorized access and brought in outside experts. The company confirmed that some personal information and tracking data were exposed but said it had found no evidence that login credentials, financial information or users' private chats were taken. It said it was notifying affected users where appropriate. Although Tinder appeared in some headlines, the hackers' claims centered on Hinge, Match and OkCupid data.

The breach was part of a broader ShinyHunters campaign in early 2026 that targeted SSO accounts at multiple companies through vishing. Other reported victims in the same wave included Panera Bread and fellow dating company Bumble. The group had previously been linked to a string of 2025 attacks that abused access to corporate Salesforce environments, and it has become one of the most prolific data-extortion operations targeting consumer brands.

For dating app users, even data that excludes messages can be sensitive, since membership in a dating service can itself reveal relationship status or sexual orientation and expose people to harassment or blackmail. For companies, the incident reinforced that single sign-on concentrates risk: one phished login can unlock many downstream systems. Security experts pointed to phishing-resistant authentication, such as FIDO2 security keys and passkeys, as the most effective defense against this kind of attack.

More from the wire

More in Social Media.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.