Could your private Tea app data have been exposed without your knowledge?
Tea reported unauthorized access to about 72,000 images, including roughly 13,000 verification selfies or photo IDs and about 59,000 other images from posts, comments, and direct messages.
A separate security flaw reported by outlets exposed more than 1.1 million private messages. These incidents may increase the risk of identity theft, scams, harassment, and unwanted contact.
Users should check official notices, secure connected accounts, review financial activity, and avoid unofficial leak databases.
Read on to learn what happened, what information was exposed, and the steps you can take to protect yourself now.
What is the Tea App and Why Did It Collect IDs?
Tea is a dating safety platform where women can share reports and discuss men they may date. Users could post questions, warnings, and experiences while keeping their identity hidden.
Tea collected selfies and photo IDs to confirm that members met its access rules and to limit fake accounts. This created a privacy conflict.
The service promoted anonymous discussion, yet it stored identifying records behind user accounts. Since people used Tea to discuss safety, relationships, and concerns, they had reason to expect strict data protection.
The breach showed how identity checks can create added risk when stored records are exposed.
Tea App Data Breach at a Glance
These key facts show when the Tea breach occurred, what data was exposed, who was at risk, and what support Tea later officially offered to affected users.
| Detail | Confirmed Information |
|---|---|
| Discovered/reported | Between July 24 and July 26, 2025 |
| First reported in | Late July 2025 |
| First exposed system | An older/unsecured Firebase storage bucket that held verification files and app images |
| Total images involved | About 72,000 |
| Verification images | About 13,000 selfies and photo IDs |
| Other images | About 59,000 images from posts, comments, and messages |
| Second exposure | More than one million private messages |
| Users were first named as affected | Accounts created before February 2024 |
| Support offered | Tea said it offered two years of identity monitoring to notified users |
Reports say the exposed verification files included selfies and government ID photos.
What Happened in the Tea App Data Breach?
The Tea app data breach involved two separate security failures: one exposing stored images and another allowing access to private messages users shared online.
The First Tea App Security Incident
Unauthorized users reportedly reached a Firebase-managed storage location used by Tea. It held verification records and images uploaded through the app.
Tea said the system was an older storage area containing records from accounts created before February 2024.
About 72,000 images were involved, including verification selfies, photo IDs, and pictures from posts, comments, and direct messages.
The incident raised serious concerns because some verification files contained sensitive personal identity details.
The Second Exposure Involving Private Chats
A separate security flaw reportedly affected Tea’s private messaging system. According to 404 Media, a logged-in user could access other users’ messages because the API failed to enforce proper access checks.
More than one million messages were reportedly exposed. Some included details users had shared themselves, such as names, social media handles, phone numbers, and personal conversations.
Tea later took its messaging system offline after the second exposure was reported.
What Information was Exposed in the Tea App Leak?

Tea confirmed some exposed data, reporters verified other details, and online forums carried additional claims that were not always backed by reliable public evidence.
Verification Selfies and Government Photo IDs
Tea confirmed that some exposed verification files contained selfies, driver’s licenses, passports, and other government documents.
An ID image can show far more than a number. It may include a full name, birth date, photograph, signature, and home address.
This can raise the risk of identity theft, fraud, impersonation, or unwanted contact when copied, stored, or shared outside the app.
Images From Posts, Comments, and Direct Messages
About 59,000 images from posts, comments, and direct messages were also reported to be exposed.
Users had added these pictures while using Tea’s features. Some images may already have been visible to other members in the app.
Still, access within Tea did not permit outsiders to copy, download, publish, rank, or reuse those files without consent from the people shown or involved.
Private Chats and Sensitive Conversations
Reporters found that about 1.1 million private messages may have been exposed in the second incident.
The chats covered relationships, health matters, personal safety, and claims about people discussed on Tea. Some users also shared real names, phone numbers, or social media handles.
These details could connect an anonymous profile or private conversation to a specific person outside the platform.
Home Addresses or Locations
Some users may have faced location exposure through several routes. An address could appear on a photo ID, while messages might mention homes, workplaces, or familiar places.
Reports also said certain uploaded images kept location metadata. Some reports said leaked data was used to build maps and that location details may have been exposed.
This does not mean every user’s exact home address was exposed.
Emails, Passwords, or Payment Details
Tea said email addresses and phone numbers were not accessed during the first incident involving stored images.
It also said passwords and payment details were not part of that exposure. The later message incident was different.
Some private chats contained phone numbers, names, and other contact details that users had typed themselves. These findings should be reported as separate events.
Who Was Affected by the Tea App Data Breach?
The breach did not affect every person in the same way. Risk depended on account age, message activity, and whether users were named in shared content online.
Users Who Joined Before February 2024: Tea linked the image exposure to accounts created before February 2024, but this does not mean every early user had a photo ID exposed.
Users Involved in More Recent Messages: The second database reportedly contained messages from 2023 through July 2025, so users active after February 2024 may also have been exposed.
People Mentioned in Tea Posts or Chats: People mentioned in Tea posts or chats may also have been affected through shared names, photos, phone numbers, accusations, or private relationship details.
How Users Can Check Their Exposure Safely
Start with any official notice from Tea and confirm the details through Tea’s official support channel. Check the identity-monitoring enrollment steps listed in the notice before clicking links or sharing personal data.
Review your credit reports, bank activity, and account alerts for signs of misuse. Search your own name and image online to spot copied photos, fake profiles, or public posts.
Avoid unofficial “Tea leak search” websites. These pages may collect names, email addresses, ID numbers, or device data.
Use only trusted sources, report suspected identity theft through the proper government or financial service, and act on any warning quickly.
What Tea App Users Should Do Now
These steps can reduce identity theft, account misuse, phishing, and personal safety risks after the Tea app breach while helping users respond through trusted channels.
1. Save the Official Notice: Keep Tea’s official notice and use its listed steps to enroll in two years of CyEx Financial Shield monitoring. Ignore enrollment links in unexpected messages.
2. Freeze Credit or Place a Fraud Alert: A credit freeze limits access to your credit report, while a fraud alert asks lenders to verify your identity. Both are free, but freezes require all three bureaus.
3. Contact the Correct ID Authority: Contact your state motor vehicle agency if driver’s license data was exposed. For passport concerns, follow the current State Department steps before reporting the document lost.
4. Secure Email and Social Accounts: Use unique passwords, enable multifactor authentication, monitor active sessions, remove public phone numbers, and watch for unexpected password resets or fake profiles.
5. Watch for Phishing and Impersonation: Treat messages that mention leaked details as suspicious. Verify anyone claiming to represent Tea, police, monitoring services, banks, or other financial companies.
6. Address Harassment and Safety Risks: Save screenshots of threats, record dates and usernames, request removal from platforms, tighten privacy settings, and contact local police when a threat appears credible.
7. Report Confirmed Identity Theft: Report confirmed misuse at IdentityTheft.gov to receive a recovery plan. Follow its steps to contact companies, place alerts, and document fraudulent accounts or charges.
Tea App Leak Lists and GitHub Pages
A “Tea app leak list” may refer to unofficial databases, maps, search tools, copied records, or downloadable files. Tea has not released a public list of every affected user.
Some GitHub repositories and other online pages reportedly contained code used to sort or display leaked material. This article does not name or link to them.
Leaked selfies were also reportedly reused on voting, ranking, and swipe-style sites without consent. These pages should not be treated as entertainment or trusted exposure checkers.
Unofficial search tools may collect names, emails, device details, or payment data, creating another privacy risk for users.
Was the Tea App Data Breach Caused by Vibe Coding?
The phrase “Tea app data breach vibe coding” spread after online comments and a statement linked to someone involved in exposing the database.
Some reports then tied the incident to rushed or AI-assisted software work. The confirmed problems were an exposed storage system and weak access controls around private messages.
Public reports do not prove that generative AI created the faulty code. Barracuda also said it was unknown whether Tea used vibe coding.
The safest conclusion is clear: the breach raised questions about coding practices, but no public forensic report has definitively shown that AI-generated code caused it.
Tea’s Response, Legal Claims, and Current Status
Tea investigated the breach, contacted law enforcement, paused messaging, offered user support, faced lawsuits, and later returned through new web and Android services in 2026.
- Investigation and Law Enforcement: Tea said it hired outside cybersecurity experts, investigated the incident, secured affected systems, and notified law enforcement after finding unauthorized access in July 2025.
- Messaging System Shutdown: Tea took its direct messaging system offline after learning that some private messages had been accessed, limiting use while the company reviewed the second security issue.
- Identity-Monitoring Support: Tea offered users who were notified two years of identity monitoring through CyEx Financial Shield, with enrollment details provided in its formal breach notice.
- Legal Claims: Several lawsuits alleged that Tea was negligent, failed to protect privacy, and delayed notice. These remain allegations, and public reports did not show final court rulings.
- Company Security Claims: Tea later claimed it tightened internal safeguards, strengthened access controls, expanded monitoring, and conducted external security testing, including penetration testing.
- Continued Expert Concerns: Security experts quoted by WIRED still advised caution, noting that stronger controls do not erase past failures or eliminate risks associated with sensitive data.
- Web and Android Return: Tea relaunched a web version in January 2026, and reporting in January 2026 said the Android app remained available on Google Play.
- Current App Availability: Tea’s Android app has remained available on Google Play, while the app was reported missing from the Apple App Store after the breach.
Safety Tips to Protect Your Data in the Future
Protecting your data starts with sharing less personal information on apps. Avoid posting phone numbers, home addresses, workplaces, daily routines, or other details that are not required.
Use a different password for each account and enable multifactor authentication. Before uploading an ID or photo, check why the app needs it, how long it keeps it, and who can access it.
Remove location data from photos and review active sessions often. After any breach, use official notices and trusted support channels.
Monitor your accounts, freeze your credit when needed, and avoid unofficial leak-search sites that may collect additional personal data.
Conclusion
The Tea app data breach shows how quickly private records can create identity, privacy, and safety risks when security controls fail.
Users should rely on official notices, secure their accounts, review credit activity, and avoid unofficial leak tools or copied databases.
Tea’s response and later security claims matter, but users should still watch for scams, impersonation, harassment, and misuse of personal images.
Legal cases and investigations related to the breach are ongoing. Share your thoughts or questions about the Tea breach in the comments below today.
Frequently Asked Questions
Is the Tea App Illegal?
The Tea app is not automatically illegal because of the breach. Still, specific posts or data practices may break privacy, harassment, or defamation laws.
Can You Check If You Had a Data Breach?
Yes, but there is no safe public Tea user list. Check official notices, Tea support, credit reports, and account alerts. Avoid unofficial leak-search sites.
Can You Sue the Tea App for Defamation?
Possibly. You generally need a false factual statement about you to be published that caused harm. Claims against Tea may face added platform-law issues. Ask a local lawyer.












