Breach report
Social MediaTea (Tea Dating Advice)
Dating safety app Tea breached, exposing 72,000 user images
Tea, a viral app where women anonymously review men they date, exposed about 72,000 images including 13,000 selfies and ID photos after an unsecured legacy database was found and shared on 4chan.
Reported by TechCrunch
Records exposed
72K
72,000 images (including about 13,000 selfies and photo IDs)
Scale vs. largest on file
- When
- 2025
- How they got in
- Unsecured legacy cloud storage
- Sector
- Social Media
In late July 2025, Tea, a women-only app that lets users anonymously share warnings and reviews about men they have dated, confirmed that it had suffered a data breach. The disclosure came as the app was surging in popularity and briefly sat at the top of Apple's free App Store chart. Tea said about 72,000 images had been accessed without authorization.
Roughly 13,000 of those images were selfies and photos of government-issued identification that women had submitted to verify their accounts, the core promise that made Tea feel safe to its users. The remaining 59,000 or so images came from posts, comments and direct messages. The company said the exposure affected people who had signed up before February 2024 and that emails and phone numbers were not included.
The breach came to light when users on the message board 4chan began circulating the images and claimed to have found an open database belonging to the app. Reporting indicated that the files sat in a legacy cloud storage system that had been left publicly accessible without authentication. Within days, leaked selfies appeared on sites that invited people to rate the women's appearance and on maps that attempted to plot users' locations. Tea said it had engaged outside cybersecurity experts and closed the vulnerability.
The situation worsened when researchers reported a second exposure involving a large volume of private messages exchanged on the platform, some containing highly personal details. Tea subsequently acknowledged that some direct messages had been accessed and temporarily disabled its messaging feature. Multiple proposed class action lawsuits were filed in US federal court, accusing the company of failing to protect sensitive data, particularly the ID images it had collected for verification.
The Tea breach became a flashpoint in debates over identity and age verification online. Collecting government IDs is increasingly required by apps and by law, yet every stored ID photo becomes a high-value target. The incident showed that verification data should be deleted once its purpose is served, that legacy storage needs the same protections as production systems, and that apps built around user safety carry an especially high duty of care.