Data breach
Match Group
- Records
- 84,847
- Breach date
- 27 January 2026Estimated
- Added
- 30 January 2026
What was exposed
2 types of data · 1 more reported
- Email addresses84,847
- Phone numbers223
- IP addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
ShinyHunters, an extortion group, published a listing on its dark web leak site in late January 2026 claiming it had stolen more than 10 million records from Match Group, the parent company of dating platforms including Hinge, Match.com, and OkCupid. Match Group confirmed to reporters that it was investigating what it called a "recently identified security incident" and that some user data had likely been accessed, while describing the exposure as limited. Our investigation team indexes this listing with 84,847 email addresses and 223 phone numbers, and estimates the breach occurred around January 27, 2026.
January 26, 2026: The Register reported that researchers had linked ShinyHunters to a campaign abusing stolen Okta single sign-on credentials affecting roughly 100 organizations.
January 29, 2026: The Register reported the leak site listing claiming "over 10 million lines" of data tied to Hinge, Match.com, and OkCupid, and pointed to AppsFlyer, a marketing analytics provider, as the apparent source of the exposure.
January 29, 2026: Match Group confirmed it was investigating the incident and had acted quickly to terminate unauthorized access, according to a statement given to The Register.
What Information Was Compromised?
Our analysis found the following data types in this breach: 84,847 email addresses and 223 phone numbers.
According to security news outlet Cybernews, which analyzed samples tied to the listing, the trove also appears to include personal customer data, some employee details, and internal corporate material. Its review flagged Hinge subscription information in the mix, including user IDs, transaction IDs, amounts paid, and records linked to blocked installations, alongside IP addresses and location data.
Not every individual is affected by every type of data listed here.
Match Group's statement said there was no indication that user login credentials, financial information, or private communications were accessed. The company declined to say what types of data were accessed, how many customers were affected, or whether a ransom demand had been made or paid, as reported by The Register.
What Are the Potential Risks for Affected Individuals?
Email addresses in criminal hands are typically used for phishing, and Match Group itself is notifying affected individuals about the risk of secondary phishing attacks. People who used the same email on dating platforms should expect messages that impersonate the company, its apps, or security teams, and should not click links or provide login details in response.
The reported exposure of IP addresses, location data, and subscription transaction details could also support targeted scams or attempts to pressure individuals, since dating app activity is personal for many users. Because internal corporate documents and some employee details were reportedly included, phishing aimed at Match Group staff or contractors is another plausible follow-on.
There is no confirmed evidence that passwords or payment card numbers were taken, but anyone who reused a dating app password elsewhere should still change it as a precaution.
What Is Match Group Doing in Response?
In its statement to The Register, a Match Group spokesperson said the company "acted quickly to terminate the unauthorized access," continues to investigate with the assistance of external cybersecurity experts, believes the incident affects a limited amount of user data, and is already notifying individuals as appropriate. The company declined to disclose affected data types, customer counts, or ransom details.
What Should You Do If You Were Affected?
Watch for phishing emails that mention Match Group, Hinge, Match.com, OkCupid, or account security. Verify any alert by going directly to the app or official website rather than clicking links in a message.
Change your password on affected dating accounts and anywhere you reused it, and enable two-factor authentication where available.
Be cautious with unexpected calls or messages referencing your account, subscription, or payment history, since transaction details and contact information were reportedly part of the leaked samples.
Monitor your email and accounts for unusual sign-in activity or password reset requests you did not initiate.
If you receive a breach notification from Match Group, follow its instructions and treat any linked urgency as a reason to verify, not to click.
