Tea app, where women rate dates with men, suffers hacker attack; understand how it works
On Friday, July 25, 2025, the Tea app, a platform for women to anonymously review their dates with men, was hit by a hacker attack that compromised the security of 72,000 user images, including selfies and identification documents. With over 4 million users in the United States, the app, a top download on the App Store, now faces a trust crisis after the exposure of sensitive data. The breach, detected in a legacy system, affected accounts created before February 2024 and included private messages, raising concerns about privacy and digital security. The company announced collaboration with the FBI and cybersecurity experts to investigate the incident and promised free identity protection support for affected users. The breach highlights vulnerabilities in platforms handling personal information and reignites debates about security in dating apps.
Tea stands out for offering a safe space for women to share relationship experiences, promising anonymity and security. The proposal attracted millions of users, but the leak exposed serious flaws in data protection.
- Key compromised data: 13,000 selfies and verification documents; 59,000 images from posts and messages.
- Company actions: investigation with experts and authorities, plus support for affected users.
- Immediate impact: loss of trust and questions about the safety of similar apps.
The incident gained traction on forums like 4chan, where leaked images were shared, increasing risks for users.
How the Tea app works and its security promise
The Tea app was designed as a support network for women, allowing anonymous reviews of men based on dating experiences. To ensure female-only access, registration requires a selfie, date of birth, and location, plus an identification document. The platform claims to verify criminal backgrounds and authenticate information, serving as a complement to apps like Tinder and Bumble.
Users praise Tea for protecting against problematic behaviors, such as lies or abuse, while men criticize its potential for defamation. The company emphasizes in its terms of use that defamatory content is prohibited, but weak moderation has been questioned.
Cobertura completa: EUA
- Core features: name-based search, reviews with green or red flags, identity verification.
- Goal: promote safety and transparency in relationships.
- Criticisms: risk of misuse for personal attacks or false information.
The app’s popularity surged in 2025, driven by viral TikTok videos, but the recent incident has challenged its ability to deliver on its security promise.

Details of the hacker attack
The hack was identified on Friday, July 25, 2025, when the company detected unauthorized access to a legacy system. According to the platform, 72,000 images were compromised, including 13,000 selfies and verification documents and 59,000 images from posts, comments, and private messages. On Monday, July 28, the company revealed that more recent private messages were also accessed, and hackers sent notifications to users.
The incident was amplified by discussions on forums like 4chan, where users shared links to download the leaked images. The severity escalated with the potential identification of users, as messages covered sensitive topics like personal experiences and reports.
- Critical points of the breach:
- Selfies and documents expose users to identity theft risks.
- Private messages contain sensitive information, like relationship accounts.
- Hacker-sent notifications indicate deep system flaws.
- Vulnerable legacy system suggests negligence in security architecture.
The company took the affected system offline and hired cybersecurity experts to strengthen protection, but the damage to its reputation was done.

Reactions and company measures
Tea’s response to the breach included immediate actions to mitigate damage. The platform stated it is working with the FBI and security experts to investigate the attack’s origin and identify those responsible. It also announced free identity protection support for affected users to reduce risks of scams and fraud.
Despite these efforts, user trust has been shaken. Many expressed concerns about the exposure of personal data, while others questioned whether to continue using the app. The company issued statements reinforcing its commitment to security but did not detail plans to prevent future incidents.
- Measures announced by Tea:
- Collaboration with the FBI to track attackers.
- Hiring cybersecurity experts.
- Free identity protection services.
- Removal of the vulnerable system.
The lack of transparency about the full extent of the breach and the absence of a clear timeline for security improvements drew further criticism.
Risks to users
The leak of 72,000 images, including selfies and identity documents, poses a significant threat to users. Cybersecurity experts warn of potential identity theft, social engineering scams, and even extortion, especially given the sensitive nature of private messages.
The exposure of personal data, such as faces and location details, increases risks of online and offline harassment. Some users reported fears of retaliation, as the app allows sharing negative experiences about men, which could lead to conflicts.
Acompanhe: tudo sobre data breach
- Key identified risks:
- Identity theft using selfies and documents.
- Targeted scams based on private messages.
- Harassment due to user identification.
- Loss of promised anonymity.
Recommendations include monitoring accounts, enrolling in credit protection services, and staying alert to suspicious contact attempts.
Legal implications and lawsuits
The breach triggered lawsuits against Tea. Two class-action lawsuits were filed in the Northern District of California Court on July 28, 2025. One, filed by Griselda Reyes, alleges her photos were accessed due to the company’s negligence. The other, filed by an anonymous user, includes platforms like 4chan and X as defendants for facilitating the spread of leaked data.
The lawsuits demand that Tea implement robust encryption, delete unnecessary sensitive data, and compensate affected users. Lawyers argue that inadequate protection, such as unencrypted document storage, constitutes gross negligence.
- Lawsuit demands:
- Mandatory encryption for sensitive data.
- Deletion of non-essential personal information.
- Financial compensation for affected users.
The outcomes of these lawsuits could influence regulations for apps handling personal data, particularly in the dating industry.
Debate on dating app security
The Tea incident has reignited discussions about the security of platforms collecting sensitive data. Despite its innovative proposal, the app revealed vulnerabilities that expose users to significant risks. The App Store, where Tea leads downloads, also faces criticism for not detecting security flaws before approving the app.
Experts highlight that the case underscores the need for regular audits, advanced encryption, and clear data storage policies. Trust in dating apps hinges on robust protection practices, which Tea failed to deliver.
- Measures suggested by experts:
- Security audits before app launches.
- End-to-end encryption for sensitive data.
- Transparency about data storage and usage.
- Staff training for incident response.
The case could accelerate stricter regulations for digital platforms, especially in the U.S. and European Union.
Tea’s future and industry lessons
Tea faces the challenge of regaining user trust while navigating lawsuits and investigations. The platform remains active, but its damaged reputation may hinder growth. The incident serves as a warning to other companies in the sector, which must prioritize security from the outset of product development.
Tea’s popularity reflects demand for solutions promoting safety in relationships, but the breach shows that good intentions don’t replace robust technological infrastructure. Implementing preventive measures will be critical for the app’s future.
- Lessons for the industry:
- Security as a strategic priority.
- Regular vulnerability testing.
- Transparent communication during crises.
- Compliance with data protection laws.
The Tea case underscores that data protection is not just a technical issue but an ethical commitment to users.

















