news

Tea Dating App’s Data Breach Exposes Users, Shattering Safety Promises

· Livio Andrea Acerbo

Tea, the viral “dating safety” app that encouraged women to share candid stories, warnings, and experiences about men, is facing a crisis that starkly contrasts its original promise of safety and confidentiality. In July 2025, Tea suffered two major data breaches that exposed the private information of tens of thousands of its users—ironically putting at risk the very people it was designed to protect[1][2][3].

The Promise of Tea: A Safe Space to “Spill the Tea”

Tea, also called “Tea Dating Advice,” positioned itself as a platform empowering women to exchange information about men they had dated or met. The app’s core appeal was its invite-only nature and its strict “no men allowed” policy, which allegedly provided a secure environment for women to:

  • Warn each other about potentially dangerous or abusive men
  • Share experiences and red flags
  • Conduct informal background checks and criminal record searches on potential dates

Users were encouraged to “spill the tea”—that is, to share stories, screenshots, and even photos about their romantic experiences. To foster trust and exclusivity, Tea required new users to verify their identities by uploading selfies and official IDs such as driver’s licenses[1][3].

The app quickly grew in popularity, boasting over 1.6 million users and topping app charts, as women flocked to a space where they could supposedly speak freely and look out for one another[1][3].

The Data Leaks: From Safe Haven to Security Hazard

That sense of safety was shattered in July 2025 when news broke that Tea’s databases had been breached—not just once, but twice in rapid succession[1][2][3].

First Leak: Images, IDs, and Messages Exposed

The initial breach involved unauthorized access to a legacy database, affecting users who joined the app before February 2024[1][2][3]. The scope was staggering:

  • 72,000 images leaked: This included 13,000 selfies and government-issued IDs (like driver’s licenses) submitted for verification, and 59,000 images from posts, private messages, and comments[1][2][3].
  • 1.1 million private messages exposed: Entire conversations, some deeply sensitive, were accessible to the attacker[1][2][3].

The files began circulating on online forums like 4chan, making private photos and confidential information public[2]. This presents severe risks: not only embarrassment or reputational harm, but also the potential for identity theft, fraud, and even physical danger if abusers or stalkers gain access to sensitive data.

Second Leak: Even More Private Conversations

Just days later, a separate security researcher discovered yet another unsecured database, this time containing over a million private conversations from early 2023 through July 2025[1]. This data included deeply personal messages exchanged between users, further compounding the breach of trust.

Why the Breach Matters

The Tea app breach is particularly egregious because of the type of data exposed and the context in which it was shared. Unlike a generic social network, Tea’s very purpose was to provide a sanctuary for women to discuss safety concerns and share potentially life-saving warnings. Users submitted their most private stories and personal documents under the assumption of security and confidentiality.

“The app was the subject of two major data leaks in July 2025, in which users’ photographs, messages and personal information were leaked,” notes Wikipedia[2]. According to a CNN report, the exposed data could be used for facial recognition spoofing, biometric fraud, deepfakes, and more[2]. Security experts warn that biometric data “doesn’t expire”—unlike passwords, you can’t change your face or your driver’s license number easily[2].

Ted Miracco, CEO of Approov, condemned the company for “rushing to market” and failing at basic cybersecurity, saying, “They promised consumers a safe site, and instead they exposed them”[2].

How Did This Happen?

Reports indicate that the backend database was “completely unsecured and without a password or any form of data encryption”[2]. The company claims the first breach only involved data from before February 2024 (prior to an infrastructure upgrade), but the discovery of a second, separate breach raises further concerns about ongoing security practices[1][2].

Worse, some of the leaked data included user verification information that, according to researchers, should have already been deleted per the app’s own terms of service[2]. This suggests not just negligence, but possible regulatory non-compliance, increasing the likelihood of lawsuits and class actions.

Lessons and Fallout

The Tea breach is a sobering reminder that even apps designed with the best intentions can expose users to harm if security is not prioritized. In trying to create a platform where women felt free to “spill” sensitive information, Tea failed to protect that information—putting its users at risk of harassment, doxxing, and worse[1][2][3].

For now, privacy advocates and cybersecurity experts urge anyone affected to monitor their credit reports and be vigilant for identity theft, especially since leaked biometric data can’t simply be changed. The breach will likely have long-term consequences for both the company and the broader landscape of digital safety apps.

Ultimately, the Tea debacle underscores a harsh truth: When you encourage users to spill their most sensitive secrets, you must be absolutely certain those secrets cannot be spilled any further[1][2][3].


Original source: NPR News – Tea encouraged its users to spill. Then the app’s data got leaked

Comments are closed.

Search

Press Enter to search · Esc to close