Tea app suffers breach, exposing thousands of user images
Tea, an app that claims to help women "make sure your date is safe, not a catfish and not in a relationship," is experiencing a security breach. 404 Media reports that a database posted on 4chan allowed anyone to access users' data. (It's since been removed.) The dataset included thousands of images, including driver's licenses.
4chan users claimed the data came from an exposed database hosted on Firebase, Google's app development platform. 404 Media verified that the exposed storage bucket URL matches one found in Tea's Android app.
The company confirmed the breach. In a statement to 404 Media, Tea said it "identified unauthorized access to one of our systems and immediately launched a full investigation to assess the scope and impact." The company stated that the exposed information included data from over two years ago. It included 72,000 images, including selfies, photo IDs and pictures from app posts and DMs.
"This data was originally stored in compliance with law enforcement requirements related to cyber-bullying prevention," Tea said. "We have engaged third-party cybersecurity experts and are working around the clock to secure our systems. At this time, there is no evidence to suggest that current or additional user data was affected. Protecting our users' privacy and data is our highest priority. We are taking every necessary step to ensure the security of our platform and prevent further exposure."
The app allows users to post photos of "red-flag" men. "Already swiping for dates on Tinder, Bumble, Match or Hinge?" the app's Play Store pitch reads. "Tea is a must-have app, helping women avoid red flags before the first date with dating advice and showing them who's really behind the profile of the person they're dating."
Its Play Store listing highlights a reverse phone number lookup. It has sections for men's real names, ages, addresses, social profiles and relationship statuses. Other features include a reverse image search and background checks to help women "get the tea on your date." Users can poll others about whether they should date new matches.
The app requires new users to submit a verification selfie and a photo of their government-issued ID. Tea told 404 Media that it uses this to verify that new signups are indeed women.
The timing of the breach coincided with the app's surge in popularity. According to Business Insider, Tea hit the top of Apple's App Store this week. The app first launched in 2023.
This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/tea-app-suffers-breach-exposing-thousands-of-user-images-190731414.html?src=rss
Tea, an app that claims to help women "make sure your date is safe, not a catfish and not in a relationship," is experiencing a security breach. 404 Media reports that a database posted on 4chan allowed anyone to access users' data. (It's since been removed.) The dataset included thousands…
Recent Posts
- Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
- Apple begins requiring age verification for App Store use in Texas
- Apple is bringing age verification to Texas this week
- How to watch NBA Finals 2026: Free streams, schedule, TV channels for New York Knicks vs San Antonio Spurs
- WiiM expands its whole-home ecosystem with a new soundbar
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023