top of page
Untitled design (1).png

A Phone Call, an Analytics Platform, and 10 Million Dating App Records

  • Writer: Syed Adnaan
    Syed Adnaan
  • Aug 13
  • 2 min read

On January 27–28, 2026, the extortion group ShinyHunters posted a claim to its dark web leak site: over 10 million records stolen from Match Group, the company behind Hinge, OkCupid, and Match.com — along with a 1.7GB sample archive to back it up.


The attack chain

Public reporting reconstructs the intrusion as follows:


  1. A vishing call targeted a Match Group employee with Okta single sign-on access.

  2. The employee’s credentials and MFA approval were compromised.

  3. The attacker authenticated into Match Group’s Okta SSO environment.

  4. From there, they pivoted into AppsFlyer, a third-party mobile analytics platform, plus corporate Google Drive and Dropbox accounts.

  5. Bulk data — user IDs, device data, Hinge transaction logs — was exported and staged.

  6. The data was posted to a leak site on January 27, 2026.

  7. Match Group confirmed a breach the following day, while disputing the scope.


What’s confirmed vs. disputed

Match Group has been consistent in what it says was not touched: login passwords, financial account numbers, and private in-app messages. What researchers who reviewed the leaked sample did find included user IDs, IP addresses, Hinge subscription transaction records, internal employee emails, and corporate documents — some reportedly tied to Vivaldi, a dating app for Indian audiences.


Notably, ShinyHunters’ claim named Hinge, Match.com, and OkCupid specifically but never mentioned Tinder, despite it being part of the same corporate family — a detail that raises questions about how far the AppsFlyer compromise actually reached.


AppsFlyer, for its part, disputed being the source of the incident, telling reporters the leak “did not originate from AppsFlyer, nor did it involve a data breach, security incident, or compromise of AppsFlyer’s systems.”


Why this one stings differently

Dating-app data carries a distinct extortion premium. Unlike a retail loyalty database, records tied to a dating platform touch on relationships, sexuality, and personal circumstances people may not want exposed — which is exactly why groups like ShinyHunters gravitate toward these targets even when financial data isn’t in scope.


This breach was one entry in a broader ShinyHunters vishing campaign against Okta, Microsoft, and Google SSO accounts across more than 100 high-value organizations in early 2026, using fake internal login portals to harvest credentials in real time.


Why it matters

Key takeaways: - SSO consolidation is efficient — and it’s also a single point of catastrophic failure when an employee is socially engineered. - Third-party marketing and analytics platforms (like AppsFlyer here) are increasingly the actual blast radius of a “company X breach” headline. - Phishing-resistant authentication — FIDO2 hardware keys or passkeys — remains one of the only methods researchers say this class of vishing attack hasn’t reliably defeated.


Sources: BleepingComputer, UpGuard, Global Dating Insights, and Malwarebytes.



 
 
 

Recent Posts

See All

Comments


bottom of page