Tea says hackers accessed a database from more than two years ago, leaking 72,000 images, including 13,000 verification photos and images of government IDs
The viral app requires new users to take selfies, which it says it deletes after review. — Hackers have breached the Tea app …
NBC News
Context & Ripple Effects
Tea’s rapid rise as a women-focused dating-safety app made its identity-verification flow central to its proposition. A claimed breach by 4chan users had already put its handling of selfies and driver’s-license images under scrutiny.
The incident became more consequential as later coverage described a separate exposure of more than 1.1 million Tea messages. Together, the reports test whether an app built around sensitive user-submitted information can retain trust while scaling.
First-order effects
People whose verification photos or government-ID images were in the older database face exposure of highly sensitive identity material, while Tea must respond to users’ questions about how such data was retained and secured.
Tea’s safety positioning is immediately strained: the breached material is closely tied to the verification process users encounter when joining the service.
Second-order effects
The breach raises the cost of user acquisition and retention for Tea, particularly as the app’s growth has made it a prominent destination; privacy assurances become a more important factor in whether users provide verification material.
The later message-data exposure compounds the first incident rather than isolating it, increasing pressure on Tea to demonstrate that both identity records and private in-app communications are protected.
Third-order effects
If identity checks become standard for safety-oriented consumer apps, the collection, retention, and protection of IDs and selfies will become a defining product-risk trade-off rather than a back-office compliance task.
Repeated incidents could shift competition in this category toward services that minimize retained sensitive data and can credibly explain their security practices; the corpus does not establish whether Tea will make that shift.
The trend: Consumer safety apps are increasingly being judged not only on the protections they promise users, but on whether their handling of identity and private communications undermines those protections.
Do not give random new apps your personal information, ESPECIALLY photos of your ID — This atrocious. Apparently the app was “vibe coded,” which shouldn't even be a thing, let alone a thing that results in a launched production app with identity verification. — www.nbcnews.c…
Looking at you Australia's and UK's User ID laws. — “Hackers leak 13,000 user photos and IDs from the Tea app, designed as a women's safe space” www.nbcnews.com/tech/social- ...
Update: the Tea app has been hacked, and 72,000 images from the app have been leaked, including verification selfies and photos of users' driver's licenses — www.nbcnews.com/tech/social- ... [embedded post]
A website getting hacked and losing 13,000 “verification photos and images of government IDs” in the same week the age verification nonsense comes into force for the #OnlineSafetyAct is fitting. Because that's what we will see a whole lot more of... to protect the children. — …
NEW FROM ME: The # 1 app spills Tea—and user verification IDs This is only the latest breach of age and ID verification data. It's an inevitability. They left where they kept IDs and selfies wide open without any security, violating their privacy policy. [image]
Even my 13-year old daughter immediately saw the problem as I explained this app to her: “so people can post photos of other people without their permission and gossip about them?” The whole premise of this is out of step with modern views on privacy... and now they're breached.
@GergelyOrosz Apparently the company claimed this only affected users who joined prior to February 2024, which makes me suspect that this is a case of just plain-old bad engineering, no vibes involved
Digging deeper, this is just layers of cluster fuck: a service for non-consensual sharing of pics and defamation requiring selfies and ID docs of participants ostensibly for their “safety” leaked and abused by parties now extensively sharing and shaming them. Ugh.
Calling the Tea hack a “hack” is honestly a stretch. They put everything in a publicly accessible DB. Not in the “they didn't encrypt” sense, in the “literally publicly accessible URL” sense. The “hack” is downloading the .jpg files from a publicly accessible URL. [image]
Calling it a “hack” is quite generous to the company behind this app, which simply left these files in a publicly accessible cloud storage bucket waiting for someone to find
Chat, the Tea App thingy continually gets worse and worse. As data dump nerds review the data, they discovered geolocation data tags some women at top-secret United States military bases (working on flight lines?) OSINT accounts and military nerds going schizo right now [image]
Tea App puts out a statement regarding the compromise. They assert it is mostly older data, but not too old but not too new (?). However, data dump nerds contend data is present in the dump from 2025 which conflicts with the statement from the developers. [image]
The drivers licenses leaked today from the tea app have been uploaded to a searchable map.... this may be the worst PII leak I've ever seen lol [image]
The Tea app has been hacked, and you can go download 59.3 gigabytes of user selfies right now. The hack is real. A picture from someone I know who signed up just to see what was on there was in it. This was an obviously vibe-coded app and was bound to be insecure. [image]