Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Leaks » Threat Actor Claims to Sell Data of 127 Million Badoo Users on Dark Web

Threat Actor Claims to Sell Data of 127 Million Badoo Users on Dark Web

Last updated:August 14, 2026
Human Written
  • A threat actor announced the sale of a dataset of millions of records of Badoo users on a dark web cybercrime forum.

  • Security professionals are unsure of the authenticity of this claim since there is no technical evidence from the hacker selling this dataset.

  • Analysts suggest the database may include publicly accessible information or reused files from previous data breaches.

Threat Actor Claims to Sell Data of 127 Million Badoo Users on Dark Web

A cybercriminal has declared that they have possession of a huge database with over 127 million records of users who are linked to the Badoo platform. Badoo is a widely known site for dating and relationships with millions of users worldwide.

An anonymous seller listed the database on a dark web marketplace recently. The posting claims that the seller holds complete user profile details for 127,380,566 members.

Security analysts quickly urged caution regarding these public claims. The online post shows no technical proof explaining how anyone extracted the file. Cybersecurity researchers urge people to treat the post as an unproven seller statement for now. Official sources have not confirmed any system breach on Badoo servers.

Details Behind the Cybercrime Forum Listing

The online advertisement emerged on a popular cybercrime forum used by active hacker groups. The seller asserts that the file contains full information from user profiles. However, the forum advertisement lacks sample records to back up the bold claim.

The Badoo listing follows a similar pattern to a much larger dark web claim from February 2026, where a threat actor advertised 600 million Tinder user records for sale, claiming the dataset contained user IDs, email addresses, password hashes, names, gender and sexual orientation, birth dates, cities, match statistics, and IP addresses.

Cybercriminals frequently post exaggerated statements to attract buyer interest or boost their online reputation. They seek quick payments from inexperienced purchasers on underground channels.

Security teams closely monitor dark web forums for potential database trades. Moreover, threat intelligence workers analyze these sales to verify stolen data sets. The listing lacks details on whether the actor used stolen initial access credentials or exploited a system vulnerability.

Sellers usually provide small proof files to demonstrate that their database is genuine. The missing proof makes validation difficult for independent analysts. Without sample data, no one can verify the authenticity of the records.

Unverified claims on underground websites often turn out to be untrue or reused data. In reality, malicious crooks frequently post previously released information under different names to swindle potential purchasers. The attacker didn’t specify when these personal details were gathered.

It is impossible to figure out if the data refers to current activity on the platform or if it is an old one. Security specialists underline that it is important for buyers and analysts not to trust these posts before experts validate them.

Scraped Content and Historical Breaches

The alleged dataset could come from automated web scraping routines rather than direct server hacks. Automated bots often gather publicly visible profile information across popular dating platforms. Scraping gathers names, general locations, photos, and public profile descriptions without breaking server security.

Meanwhile, scrapers bundle these gathered lists into massive databases for sale on illicit marketplaces. Buyers acquire these lists to build marketing leads or execute spam campaigns.

Another strong possibility points toward combined older security incidents. Historical archives listed on Have I Been Pwned show that Badoo faced an unverified breach allegation a decade ago, involving older user files.

Malicious vendors frequently blend multiple old breaches together. They re-pack these collections to create the illusion of a fresh security breach. Consequently, these combined lists contain outdated passwords and inactive email addresses from past exposures. Aggregated lists often circulate for years among cybercriminals.

Platform operators struggle to prevent large-scale data scraping due to public profile features. Dating applications let users view local profiles to connect with nearby people. That open design makes public data collection easy for scraping bots.

Companies must balance open user discovery against strict data privacy protections. Cybersecurity experts urge companies to implement rate limits on public application programming interfaces.

Guarding Personal Profiles Against Online Risks

Even leaks from unverified databases can pose serious problems for ordinary internet users. Criminals take advantage of the revealed information such as email addresses or contact numbers to carry out their fraudulent schemes. In addition, they employ the credential stuffing technique by applying the same password on other platforms.

The methodology of these attacks relies on automated software that checks the exposed login details on different online platforms, such as banking, email, and e-commerce websites. They take advantage of poor password habits to gain access to financial accounts.

Security groups advise internet users to practice good account security habits. That means individuals should use a strong password for every mobile application separately. Enabling the multi-factor authentication feature helps provide extra protection from hacking.

Users should also stay cautious when receiving unexpected text messages or direct emails. This is because scammers often use such means to trick victims into revealing sensitive personal codes.

Users can check security monitoring sites to see if their personal details appeared in known breaches. Neglecting standard online security requirements results in the risk of identity theft. Those having accounts on any platform should change their passwords at once upon learning about possible hacking of their profile.

Also, experts in security recommend that users should close those old and dormant accounts to escape the possibility of exposure on the internet. The only safe method of fighting with modern frauds is to always stay alert.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.