The Tea dating app, which utilized AI for user verification and reverse image search, suffered a major data breach of a legacy storage system. Approximately 72,000 images, including selfies and government IDs, were accessed by hackers and leaked on 4chan. This incident exposed users to potential harassment and safety risks, leading to class action lawsuits against the company.
In July 2025, the Tea dating advice app, which purportedly uses AI-assisted tools for user verification and reverse image search, reportedly suffered a breach of a legacy storage system. Hackers allegedly accessed about 72,000 images, including selfies, photo IDs, and other content, which were purportedly circulated on 4chan. The incident reportedly exposed sensitive data of users who signed up before February 2024.
Risk classification
- Primary risk domain: 2 Privacy & Security
- Primary risk subdomain: 2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive information
The incident involved the unauthorized access and leaking of highly sensitive personal information, including government IDs and selfies used for AI-based verification, directly violating user privacy.
Causal factors
- Entity: Human
- Intent: Intentional
- Timing: Post-deployment
The data breach was caused by human hackers intentionally targeting the app's legacy storage system post-deployment, combined with human management decisions regarding data retention.
EU AI Act risk tier
- Risk tier: 4 Minimal or No Risk
Minimal or No Risk: The report describes an AI system used for user verification and reverse image search in a commercial dating app, which poses minimal risk to users under normal operation.
AI system and alleged parties
- AI system: Tea dating advice app AI-assisted tools
- AI purpose: Image Verification; Face Recognition
- Behaviour type: Tool
- Alleged developer: Tea Dating Advice
- Alleged deployer: Tea Dating Advice
- Alleged harmed parties: Women, Users of the Tea app, Users of Tea Dating Advice, General public
Harm severity
Highest direct severity in any category: Substantial. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Negligible, indirect Minor
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Negligible, indirect Substantial
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Substantial, indirect Substantial
- Psychological: direct Negligible, indirect Minor
- Epistemic: direct Negligible, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
Financial
Reported: The report notes that the company faces two class-action lawsuits in California, though specific financial figures are not provided.
Directly caused: N/A
Indirectly caused: The company faces legal expenses and potential damages from two class-action lawsuits filed in California.
Inferred additional harm: The company likely suffered significant financial losses from legal defense, potential settlements, and loss of business/subscribers, while victims may have incurred costs for identity theft protection.
Malicious content
Reported: The report describes online trolls mocking and threatening the safety of the women whose personal information was leaked.
Directly caused: N/A
Indirectly caused: Trolls on 4chan and other social media platforms spread toxic content, including threats and mockery targeting the women whose data was leaked.
Inferred additional harm: Additional toxic content, such as targeted harassment campaigns or non-consensual sharing of the images, likely occurred across other online platforms.
Privacy
Reported: The report explicitly describes a major data breach exposing sensitive personal data.
Directly caused: The breach directly exposed approximately 72,000 images, including 13,000 selfies and government IDs, as well as direct messages of users who signed up before February 2024.
Indirectly caused: Trolls used the leaked metadata to attempt to map and expose the physical locations of the subscribers.
Inferred additional harm: It is likely that the leaked government IDs and personal details will be used for identity theft, stalking, or further doxxing of the affected individuals.
Psychological
Reported: The report describes threats to safety, mocking, and harassment targeting the women whose data was leaked.
Directly caused: N/A
Indirectly caused: The leak of sensitive photos and IDs led to online mocking, harassment, and threats to safety, causing distress and anxiety for the affected women.
Inferred additional harm: It is highly likely that many of the 72,000 affected users experienced significant anxiety, distress, and fear for their safety due to their private IDs and locations being exposed to hostile online forums like 4chan.
People affected
- Occurrences reported: 1
- People reportedly harmed: 72000
- People reportedly exposed: 72000
Potential causes
Management
- Prioritizing Growth Over Safety: Rapid scaling to millions of users outpaced safety infrastructure.
- Inadequate Risk Assessment: Management failed to secure legacy databases holding user IDs.
- Conflicting Privacy Policies: Stated deletion policies conflicted with actual data retention practices.
Technology
- Vulnerable Legacy Storage System: Data stored in older, less secure systems that were not properly fortified.
- Exposed Image Metadata: Metadata left in images allowed malicious actors to map user locations.
- Automated Reverse Image Search: Image-matching automation features exposed sensitive user profile photos.
Data Inputs
- Retention of Verification Selfies: Selfies and IDs were kept instead of being deleted after verification.
- Collection of Sensitive IDs: Requiring government IDs created a high-value target database for hackers.
- Unfiltered Direct Message Logs: DMs containing personal conversations were stored and subsequently leaked.
Human Factors
- Targeting by Malicious Trolls: 4chan users coordinated attacks to hack the app and leak data.
- User Reliance on App Security: Users uploaded sensitive IDs trusting the app safety promises.
- Online Mob Behavior and Gossip: Digital whisper networks amplified toxic behavior and bad-faith claims.
Process and Methods
- Failure to Delete Verified Data: Retention policy conflicted with the promise to delete verification data.
- Inadequate Data Migration: Legacy systems were excluded from security upgrades applied to new systems.
- Lack of Metadata Stripping: No process to strip EXIF location data from uploaded user images.
Regulatory Environment
- Cyberbullying Retention Laws: Law enforcement requirements led to keeping data that should be deleted.
- Lack of Data Privacy Oversight: Absence of strict regulatory oversight on sensitive ID storage.
Information quality
- Classification confidence: High
- Reason for confidence: The reports provide clear and consistent details about the data breach, the number of images exposed, the platform involved, and the subsequent consequences such as lawsuits and online harassment. The role of AI (verification and reverse image search) is clearly contextualized within the app's features.
- Ambiguities identified: It is slightly ambiguous whether '72,000 images' equates to exactly 72,000 unique users, though the extraction context treats them as 72,000 affected users.
- Alternative interpretations: The incident could be viewed purely as a cybersecurity failure of a legacy database rather than an AI safety failure, though the data leaked was collected specifically for the AI verification process.
A data breach of the Tea dating app exposed 72,000 images, including government IDs and selfies used for AI-based verification. The leaked data was posted on 4chan, leading to targeted harassment and doxxing. The incident represents a minor national security concern, primarily impacting individual privacy and highlighting security risks of retaining sensitive verification data.
- Overall national security impact: Minor
- Response level: Moderate
- Scope: Single nation
- Primary target: United States
- Alleged perpetrator: Unknown
Threat characteristics
- Imminence: Long-term. The breach has already occurred, and while victims face ongoing harassment, it does not present an imminent national security crisis.
- Autonomy: Human-controlled. The AI system functioned as a basic verification and search tool, and the breach itself was executed by human actors targeting a database.
- Novelty: Established threat. Data breaches targeting legacy databases and subsequent online doxxing are well-established cyber threats with extensive precedent.
Impact by dimension
- Physical security: Negligible. No threats to physical systems, kinetic targeting, or critical infrastructure were reported in connection with this data breach.
- Information security: Negligible. The incident was a cybercriminal data breach and subsequent trolling on 4chan, rather than a state-sponsored information warfare or intelligence operation.
- Sovereignty: Negligible. No disruption to government operations, electoral systems, or state sovereignty was observed.
- Economic security: Negligible. Impact is limited to class-action lawsuits and financial damage to a single private company, with no broader threat to strategic industries or national economic stability.
- Societal stability: Minor. Leaking of 72,000 images, including government IDs, led to targeted doxxing and harassment of women on 4chan. While serious for the victims, the national security impact is minor and manageable through standard law enforcement and legal channels.