Tea app confirms data leak after 4Chan users discover unsecured cloud storage

midian182

Posts: 10,873   +142
Staff member
What just happened? Tea, officially known as "Tea Dating Advice," is a dating safety app that allows women to anonymously share information about men and potential red flag behavior. Now the top free app in the App Store, Tea has been hacked. 4Chan users linked to a public storage bucket containing about 72,000 images, including 13,000 selfies and government-issued IDs used for gender verification.

The Tea app has seen a surge in popularity recently. Founded in 2023, it allows women to exchange details about local men in the area. This can be anything from behavior that could be perceived as warning signs, whether they are married, are registered sex offenders, have criminal records, or if they use fake images for catfishing.

Women can also share "green flag" qualities found in men.

Tea recently said that it has over 4 million members globally and became the top free app in Apple's App Store last week. But while it is advertised as being a safety app, it has received plenty of criticism. Some men claim to have been doxxed or misrepresented by women with a grudge. Others say it is "anti-male."

The app requires users to take selfies to prove they are female. Tea's privacy policy states that these photos are "deleted immediately" after authentication.

404 Media reports that 4Chan users posted links to an exposed cloud database hosted on Google's mobile app development platform, Firebase. This followed calls on the site for a "hack and leak" campaign against the app.

Members of the imageboard reportedly searched through the data, posting selfies and identities that had been uploaded to Tea. One person said they downloaded 3,000 images.

Although screenshots from the app are blocked by its security features, Tea admitted that 59,000 images showing posts, comments, and direct messages from over two years ago were also accessed.

404 Media reports that the public bucket linked by 4Chan users was the same one the publication discovered in the app's source code.

Tea says that the database was from two years ago, and that the data was originally stored in compliance with law enforcement requirements related to cyberbullying prevention.

The company added that the breach affected members who signed up before February 2024. It has hired third-party cybersecurity experts and is "working around the clock to secure our systems."

"Protecting our users' privacy and data is our highest priority. Tea is taking every necessary step to ensure the security of our platform and prevent further exposure," a spokesperson said.

This isn't the first time that 4Chan has been at the center of a leak. Images from the 2014 celebrity photo leak scandal known as "Celebgate" or "The Fappening" originated on the imageboard, though in that instance they were obtained primarily through targeted phishing attacks on Apple iCloud accounts.

Permalink to story:

 
This looks like some kind of vicious feminista network, used for discrediting any man they want. It shouldn't exist in the first place.

So pretty much like unvetted user generated videos on YouTube. The left the right, the woke. The Dems the libs the conservatives, the red state red necks.

See weirdly as I've noticed and someone finally had a video up stating too, ya want the same things most of the time, but you're taught by media and or uneducated people to hate one another instead. And the woke, I hear each side calling one another this, so I'm unsure who is on what side, and I'm not sure the media knows half the time, but woke is now the new easy go to like , conspiracy theorist, don't need to have evidence of you have that term.

The internet, brings everyone together, to hate on one another together.

Breaking down walls, to build gun towers, and croc infested moats. 😆

But who gonna police the police right? Nanny state inbound.
 
"Protecting our users' privacy and data is our highest priority. Tea is taking every necessary step to ensure the security of our platform and prevent further exposure," a spokesperson said.

Talk is cheap. All that matters if they took action to back up their words with action and clearly they did not. There should be severe legal, criminal consequences for those who hoard sensitive data and do not safeguard it. On paper, these consequences exist, but money dillutes the law.
 
Funny how it went from women badmouthing guys, to guys now knowing exactly which women to avoid.

What goes around comes around I suppose. How nice of Apple to allow an app with unsecured cloud storage that's aimed at discrediting people (without requiring any evidence) to be listed in the app store (as the #1 app even.
But when you want to put the text "if you subscribe on my Apps site instead of through the App it's considerably cheaper" - that's where they draw the line. Your app is banned.
 
The left the right, the woke. The Dems the libs the conservatives, the red state red necks.


The internet, brings everyone together, to hate on one another together.

Breaking down walls, to build gun towers, and croc infested moats. 😆

But who gonna police the police right? Nanny state inbound.


Relax, it's just that first generations born without memory of XX century fascists and their doings, like hitler, pol pot, hong weibings or some ancient left and right movements before WW1.
 
Why, anyone would use a cloud service, let alone pay for it, is way beyond me. Just get two or three 8TB external hard drives and a good imaging software, to protect your own data! It's not rocket science ...
 
So Tea made women verify their gender with selfies and IDs, stored it all in a cloud bucket, and then got surprised when 4Chan treated it like an open bar? This is like building a panic room with glass walls and handing out the floor plan on Reddit.
 
Why, anyone would use a cloud service, let alone pay for it, is way beyond me. Just get two or three 8TB external hard drives and a good imaging software, to protect your own data! It's not rocket science ...
What? Did you not read the article or do you not understand how hosting something like this works?

You reckon someone could "buy two or three 8TD external drives" and host an App that ten's of thousands of people used everyday?
 
Back