Data breach
Mate1.com
- Records
- 27,389,929
- Breach date
- 29 February 2016Estimated
- Added
- 1 December 2024
What was exposed
4 types of data · 2 more reported · 1 puts you at serious risk
- Usernames27,389,923
- Email addresses27,389,815
- Passwords27,381,661
- Names50,942
- Dates of birthReported, not counted
- Marital statusReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In early 2016, the online dating site Mate1.com suffered a data breach that exposed more than 27 million user accounts. According to our investigation team, the incident is estimated to have occurred on February 29, 2016, and involved roughly 27,389,929 records. The stolen data was later offered for sale on a dark web forum known as Hell, where a hacker claimed to have pulled the records from the site's MySQL database after gaining command access to its server. Reporting by International Business Times UK described how the seller initially claimed 40 million accounts, then removed bot accounts before offering the data for 20 bitcoin, worth roughly $8,600 at the time. The final sale price was never publicly confirmed.
February 29, 2016: Mozilla Monitor records this as the date Mate1.com was breached.
March 2016: A hacker selling the Mate1.com data on the dark web forum Hell was reported by International Business Times UK, citing a forum post seen by Motherboard.
April 15, 2016: Sophos reported that the stolen Mate1.com accounts, including plaintext passwords, had been offered for sale and were circulating online.
What Information Was Compromised?
Our analysis found the following data types in this breach: usernames (nicknames) for 27,389,923 accounts, passwords for 27,381,661 accounts, email addresses for 27,389,815 accounts, and names for 50,942 accounts. The listing contains 27,389,929 records in total.
Reporting at the time indicated the passwords were stored in plaintext rather than hashed or encrypted, meaning anyone who obtained the database could read them directly. Mozilla Monitor also lists additional profile fields connected to this breach, including dates of birth, relationship statuses, income levels, drinking and drug habits, and personal descriptions.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because the passwords were reportedly stored in plaintext, anyone who reused a Mate1.com password on other accounts faced a real risk of account takeover. Email access, banking, and social media logins are the most immediate concerns if the same password was used elsewhere.
The exposure of email addresses tied to a dating site also creates opportunities for phishing and extortion. Criminals can reference the site by name in convincing emails, since the fact that a person had an account there is itself sensitive. Full names, where present, combined with the profile details described by Mozilla Monitor, could support identity theft or targeted harassment.
What Should You Do If You Were Affected?
If you had a Mate1.com account around 2016, take these steps:
Change your Mate1.com password if the account still exists, and change the password anywhere else you reused it.
Turn on two-factor authentication for your email and other important accounts.
Watch for phishing emails that reference dating sites or ask you to "verify" account details. Do not click links in unexpected messages.
Be alert to extortion attempts that mention the site. Delete them rather than paying.
Consider a password manager so each account gets a unique password going forward.
In the news
- International Business Times UK: Mate1.com hack: 27 million account passwords and emails have been leaked and sold on dark webibtimes.co.uk (opens in a new tab)
- Sophos: Millions more adult and dating website accounts for sale on dark webnews.sophos.com (opens in a new tab)
- Mozilla Monitor: Mate1.com Data Breachmonitor.mozilla.org (opens in a new tab)
- CyberInsurance.com: Mate1.comcyberinsurance.com (opens in a new tab)
