/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Tea says hackers accessed a database from more than two years ago, leaking 72,000 images, including 13,000 verification photos and images of government IDs

The viral app requires new users to take selfies, which it says it deletes after review.  —  Hackers have breached the Tea app …

NBC News

Context & Ripple Effects

Tea’s rapid rise as a women-focused dating-safety app made its identity-verification flow central to its proposition. A claimed breach by 4chan users had already put its handling of selfies and driver’s-license images under scrutiny.

The incident became more consequential as later coverage described a separate exposure of more than 1.1 million Tea messages. Together, the reports test whether an app built around sensitive user-submitted information can retain trust while scaling.

First-order effects

  • People whose verification photos or government-ID images were in the older database face exposure of highly sensitive identity material, while Tea must respond to users’ questions about how such data was retained and secured.
  • Tea’s safety positioning is immediately strained: the breached material is closely tied to the verification process users encounter when joining the service.

Second-order effects

  • The breach raises the cost of user acquisition and retention for Tea, particularly as the app’s growth has made it a prominent destination; privacy assurances become a more important factor in whether users provide verification material.
  • The later message-data exposure compounds the first incident rather than isolating it, increasing pressure on Tea to demonstrate that both identity records and private in-app communications are protected.

Third-order effects

  • If identity checks become standard for safety-oriented consumer apps, the collection, retention, and protection of IDs and selfies will become a defining product-risk trade-off rather than a back-office compliance task.
  • Repeated incidents could shift competition in this category toward services that minimize retained sensitive data and can credibly explain their security practices; the corpus does not establish whether Tea will make that shift.

The trend: Consumer safety apps are increasingly being judged not only on the protections they promise users, but on whether their handling of identity and private communications undermines those protections.

Discussion

  • @endeavorance.camp @endeavorance.camp on bluesky
    Do not give random new apps your personal information, ESPECIALLY photos of your ID  —  This atrocious.  Apparently the app was “vibe coded,” which shouldn't even be a thing, let alone a thing that results in a launched production app with identity verification.  —  www.nbcnews.c…
  • @kat.meangirls.online @kat.meangirls.online on bluesky
    there are so many infuriating parts of this.
  • @socialmedialab.ca @socialmedialab.ca on bluesky
    Looking at you Australia's and UK's User ID laws.  —  “Hackers leak 13,000 user photos and IDs from the Tea app, designed as a women's safe space” www.nbcnews.com/tech/social- ...
  • @chronotope.aramzs.xyz Aram Zucker-Scharff on bluesky
    It's wild how the exact concern every expert has with private apps running verification keeps coming true.  [embedded post]
  • @bengoggin Ben Goggin on bluesky
    Update: the Tea app has been hacked, and 72,000 images from the app have been leaked, including verification selfies and photos of users' driver's licenses  —  www.nbcnews.com/tech/social- ...  [embedded post]
  • @tommorris@mastodon.social Tom Morris on mastodon
    A website getting hacked and losing 13,000 “verification photos and images of government IDs” in the same week the age verification nonsense comes into force for the #OnlineSafetyAct is fitting.  Because that's what we will see a whole lot more of... to protect the children.  —  …
  • @senatorshoshana @senatorshoshana on x
    NEW FROM ME: The # 1 app spills Tea—and user verification IDs This is only the latest breach of age and ID verification data. It's an inevitability. They left where they kept IDs and selfies wide open without any security, violating their privacy policy. [image]
  • @troyhunt Troy Hunt on x
    Even my 13-year old daughter immediately saw the problem as I explained this app to her: “so people can post photos of other people without their permission and gossip about them?” The whole premise of this is out of step with modern views on privacy... and now they're breached.
  • @g0adm Adam Wren on x
    I can't believe the Tea app leak exposed a secret military airbase lmao, whoever owned this company is about to get sued into nonexistence
  • @simonw Simon Willison on x
    @GergelyOrosz Apparently the company claimed this only affected users who joined prior to February 2024, which makes me suspect that this is a case of just plain-old bad engineering, no vibes involved
  • @troyhunt Troy Hunt on x
    Digging deeper, this is just layers of cluster fuck: a service for non-consensual sharing of pics and defamation requiring selfies and ID docs of participants ostensibly for their “safety” leaked and abused by parties now extensively sharing and shaming them. Ugh.
  • @austen Austen Allred on x
    Calling the Tea hack a “hack” is honestly a stretch. They put everything in a publicly accessible DB. Not in the “they didn't encrypt” sense, in the “literally publicly accessible URL” sense. The “hack” is downloading the .jpg files from a publicly accessible URL. [image]
  • @belowtearline @belowtearline on x
    Rule Number One: Do not take a selfie to sign up for a gossip app while working on the flight line at a secret military base. [image]
  • @lachlan Lachlan Markay on x
    Calling it a “hack” is quite generous to the company behind this app, which simply left these files in a publicly accessible cloud storage bucket waiting for someone to find
  • @vxunderground @vxunderground on x
    Chat, the Tea App thingy continually gets worse and worse. As data dump nerds review the data, they discovered geolocation data tags some women at top-secret United States military bases (working on flight lines?) OSINT accounts and military nerds going schizo right now [image]
  • @vxunderground @vxunderground on x
    Tea App “security” team right now (it's literally just a cat in bumble bee outfit) [image]
  • @vxunderground @vxunderground on x
    Tea App puts out a statement regarding the compromise. They assert it is mostly older data, but not too old but not too new (?). However, data dump nerds contend data is present in the dump from 2025 which conflicts with the statement from the developers. [image]
  • @ztobias114838 @ztobias114838 on x
    The drivers licenses leaked today from the tea app have been uploaded to a searchable map.... this may be the worst PII leak I've ever seen lol [image]
  • @cremieuxrecueil @cremieuxrecueil on x
    The Tea app has been hacked, and you can go download 59.3 gigabytes of user selfies right now. The hack is real. A picture from someone I know who signed up just to see what was on there was in it. This was an obviously vibe-coded app and was bound to be insecure. [image]
  • r/privacy r on reddit
    The tea app is extremely suspicious
  • r/morningsomewhere r on reddit
    Saw On A Different Subreddit That It Was For Gossiping, But The Inevitable Happened
  • r/news r on reddit
    Hackers leak 13,000 user photos and IDs from the Tea app, designed as a women's safe space
  • r/SwipeHelper r on reddit
    Tea app has been hacked!