Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » Hacker Lists 600 Million Tinder User Records for Sale on Underground Web Forum

Hacker Lists 600 Million Tinder User Records for Sale on Underground Web Forum

Last updated:July 20, 2026
Human Written
  • A cybercriminal on a dark web forum claims to sell a database containing 600 million Tinder user records.

  • Independent security researchers have not verified the authenticity or freshness of the dataset, also Match Group has issued no confirmation.

  • Dating app users should immediately update passwords, enable two-factor authentication, and unlink external social media accounts to protect their privacy.

Hacker Claims Sale of 600 Million Tinder User Records on Dark Web Forum

A digital actor claims control over a massive dating app database. Recently, the individual posted a sales notice on a hidden internet forum. This poster offers personal files belonging to 600 million profile owners.

Tinder operates as a popular worldwide matching tool for smartphone users. Every day, millions of individuals create profiles to find romance or friends.

Users share personal details like names, ages, pictures, and exact locations. A massive security incident creates severe safety risks for app members. Anyone using online matching applications must stay alert regarding personal data.

Details Included in the Advertised Data Package

The seller claims this database contains deeply private personal details. Specifically, the forum listing highlights hidden user identification codes and emails. Scrambled password hashes appear inside the offered digital package.

The file allegedly includes actual first names of registered account holders. The sensitive nature of dating app data has made platforms like Grindr targets as well, with user data reportedly listed for sale.

Besides, the seller lists birth dates alongside specific gender selections. Users also share their individual sexual orientation choices inside the app.

Furthermore, exact physical locations like towns and countries fill the records. The hacker even promises swipe actions and matching history for members. Consequently, a criminal could track how often users interact with others.

In addition, account subscription tiers and paid levels sit inside the dataset. The seller also includes total photo counts, blue identity badges, linked profiles from music services, and photo-sharing apps.

Next, the listing highlights phone operating software alongside application version details. As a result, intruders can learn which specific smartphones people carry daily. Additionally, registration timestamps and last active times appear across the files.

Registered Internet Protocol address numbers show where people made profiles. These sensitive details give bad actors complete visibility into member habits.

Therefore, compromised accounts put real-world privacy in immediate danger everywhere. In fact, matching statistics reveal intimate personal routines to complete strangers.

Lack of Verification and Potential Fraud Threats

Independent security experts have not verified these massive claims yet and currently, no technical analyst has confirmed the real source of information. The seller posted a small sample file to prove the claim.

Nevertheless, digital thieves frequently create fake samples to trick forum buyers. Therefore, industry analysts view extreme record numbers with great caution. Meanwhile, Match Group has issued no public statement confirming a breach.

The parent company manages and oversees all global Tinder operations daily. Frequently, dark web sellers invent famous brand stories to gain attention, and bad actors raise their personal profile on underground boards.

Furthermore, old leaked files often get recycled into new advertising posts – scammers can combine multiple separate old lists to generate huge record totals. So, buyers and researchers must approach unconfirmed datasets with skepticism.

Meanwhile, application members still face genuine risks if data proves real. For example, bad actors can send targeted scam emails to addresses and fraudsters send fake warning messages to trick people into typing passwords.

Furthermore, blackmailers might exploit private matching histories against targeted individuals. Therefore, profile owners should enhance their personal cybersecurity habits immediately. Online extortionists target victims using private details found in breaches.

Ways to Secure Personal Dating Profiles

Account holders should change their profile passcodes immediately, and they must create strong login phrases mixing letters and numbers. Additionally, individuals should avoid reusing identical passwords across different services. This means a single digital breach will not endanger other important accounts.

Furthermore, app users should enable two-factor security features right away. Multi-step login protections demand an extra safety code before opening accounts. So, intruders cannot enter profiles even with stolen password hashes.

Besides, members should disconnect external social media pages from dating applications. Unlinking extra accounts limits the amount of personal info exposed during leaks. Also, users must watch out for fake emails claiming official support.

Legitimate companies never request secret account passcodes inside ordinary emails. Therefore, clicking on unknown links inside text messages creates major security dangers.

 Usually, free monitoring tools inform people when personal emails appear online, and using credential checking services helps individuals detect leaked accounts fast.

Members should check account privacy options inside their application settings. Proactive safety actions help keep personal information secure against digital threats.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.