Tea, a women’s dating safety app that lately surged to the highest of the free iOS App Retailer listings, suffered a significant safety breach final week. The corporate confirmed Friday that it “recognized licensed entry to considered one of our programs” that uncovered 1000’s of consumer pictures. And now we all know that DMs had been accessed in the course of the breach, too.
Tea’s preliminary findings from the top of final week confirmed the information breach uncovered roughly 72,000 pictures: 13,000 pictures of selfies and picture identification that individuals had submitted throughout account verification, and 59,000 pictures that had been publicly viewable within the app from posts, feedback and direct messages.
These pictures had been saved in a “legacy information system” that contained data from greater than two years in the past, the corporate mentioned in assertion. “Right now, there isn’t any proof to counsel that present or extra consumer information was affected.”
Earlier Friday, posts on Reddit and 404 Media reported that Tea app customers’ faces and IDs had been posted on nameless on-line message board 4chan. Tea requires customers to confirm their identities with selfies or IDs, which is why driver’s licenses and photos of individuals’s faces are within the leaked information.
And on Monday, a Tea spokesperson confirmed to CNET that it moreover “lately realized that some direct messages (DMs) had been accessed as a part of the preliminary incident.” Tea has additionally taken the affected system offline. That affirmation adopted a report by 404 Media on Monday that an unbiased safety researcher found it might have been possible for hackers to gain access to DMs between Tea customers, affecting messages despatched as much as final week on the Tea app.
Tea mentioned it has launched a full investigation to evaluate the scope and influence of the breach.
Class motion lawsuit filed
One of many customers of the Tea app, Griselda Reyes, has filed a category motion lawsuit on behalf of herself and different Tea customers affected by the information breach. Based on court documents filed on July 28, as reported earlier by 404 Media, Reyes is suing Tea over its alleged “failure to correctly safe and safeguard … personally identifiable data.”
“Shortly after the information breach was introduced, web customers claimed to have mapped the areas of Tea’s customers based mostly on metadata contained from the leaked pictures,” the criticism alleges. “Thus, as a substitute of empowering ladies, Tea has really put them susceptible to critical hurt.”
Tea additionally has but to inform its prospects personally about their information being breached, the criticism alleges.
The criticism is looking for class motion standing, damages for these affected “in an quantity to be decided” and sure necessities for Tea to enhance its information storage and dealing with practices.
Scott Edward Cole of Cole & Van Observe, the regulation agency representing Reyes, instructed CNET he’s “surprised” by the alleged lack of safety protections in place.
“This software was marketed as a protected place for ladies to share data, typically very intimate data, about their courting experiences. Few individuals would take that danger in the event that they’d identified Tea Relationship put such little effort into its cybersecurity,” Cole alleged. “One chief aim of our lawsuit is to compel the corporate to start out taking consumer privateness much more severely.”
Tea did not instantly reply to a request for touch upon the category motion lawsuit.
What’s the Tea app?
The premise of Tea is to supply ladies with an area to report unfavourable interactions they’ve had whereas encountering males within the courting pool, with the intention of maintaining different ladies protected.
The app is at present sitting on the No. 2 spot totally free apps on Apple’s US App Retailer, proper after ChatGPT, drawing worldwide consideration and sparking a debate about whether or not the app violates males’s privateness. Following the information of the information breach, it additionally performs into the broader ongoing debate round whether or not online identity and age verification pose an inherent security risk to web customers.
Within the privateness part on its web site, Tea says: “Tea Relationship Recommendation takes affordable safety measures to guard your Private Data to stop loss, misuse, unauthorized entry, disclosure, alteration and destruction. Please remember, nonetheless, that regardless of our efforts, no safety measures are impenetrable.”

