Quasa
Use QUASA App
Join the pioneer of Web3 crypto freelancing today!
Open
Technology

Tea Still Verifies Users After Its 2025 Data Breach

|Updated: |Author: QUASA Editorial Team|5 min read| 3148
Tea Still Verifies Users After Its 2025 Data Breach

Tea’s July 2025 data breach did not end the women-focused dating-safety service. Tea remains accessible through the web and Google Play and continues to verify new users, while new downloads of its iOS app are unavailable.

The breach’s central facts also became clearer after the first reports: identity-verification records were exposed, but the evidence does not establish that Tea’s entire database was taken. The service’s continued use of facial and government-ID checks now makes data collection, retention and access controls as relevant as the original leak.

What the official breach record establishes

The incident involved unauthorized access to a file-storage location used for new-user verification. Tea’s filed consumer notice says the access occurred on or around July 24, 2025, was discovered on July 25, and prompted containment measures, notification of law enforcement, stronger security controls and an offer of two years of identity-monitoring services.

Tea found indications that most or possibly all records in that particular storage location had been accessed. Images associated with affected recipients could contain a name, date of birth, driver’s-license number, passport number or another government-identification number.

This wording is important because it defines both the severity and the boundary of the documented breach. Government identifiers can remain useful for impersonation after a password is changed, but the filing describes one verification-related storage location rather than every database, account field or internal system operated by Tea.

The official filing also does not establish that material obtained before containment was recovered or erased. Closing access to a storage location stops the same route from remaining open; it cannot by itself remove copies that outsiders may already have downloaded or redistributed.

What was linked to 4chan—and what was not proved

The Associated Press’s initial account attributed discovery of the exposed database to 4chan users, citing 404 Media, and relayed Tea’s estimate that about 72,000 images were accessed: roughly 13,000 verification selfies or selfies containing photo identification and approximately 59,000 images associated with posts, comments and direct messages.

The two groups presented different risks. Verification images could expose durable identity credentials, while post and messaging material could reveal associations, allegations or private circumstances connected to a dating-safety community.

The same account placed the affected verification records among users who registered before February 2024 and indicated that email addresses and phone numbers were not accessed in that portion of the incident. Those limits should not be expanded into a claim that no personal details appeared inside photographs, posts or message content.

Public evidence supports describing 4chan as part of the discovery and circulation story. It does not support the broader claim that the exposed material consisted only of profiles belonging to women who had criticized men, nor does it establish the motives of everyone who subsequently downloaded or shared the files.

Likewise, the available evidence is more precise than the phrase “full database leak.” The disclosed image categories were extensive, and the identity records were highly sensitive, but neither the state filing nor the contemporaneous account demonstrates that every Tea system or every category of user information was compromised.

Tea remains active, with different access on each platform

The service’s present status is not a shutdown. Tea’s current account-security instructions state that new App Store downloads are unavailable, existing iOS users need the app already installed, iPhone users can use the web version, and Android users can obtain Tea through Google Play.

Account creation still includes identity verification. The current workflow offers either a live facial check that creates a three-dimensional facial rendering or a process using a static selfie and photographs of a government ID.

The same instructions describe verification as being handled through a third party. The public page does not identify that provider or specify retention periods, deletion schedules or the storage architecture for the facial rendering, selfie and identification images.

That absence does not prove that Tea lacks internal retention or deletion controls. It means prospective users cannot determine those details from the cited public instructions, leaving an important part of the post-breach data lifecycle unexplained on that page.

Why continued verification matters

Tea’s current operation separates two questions that were often collapsed in early coverage. Product availability shows that the company continues to provide the service; it does not demonstrate what technical changes were made after the breach or whether each category of verification data is now retained differently.

Identity verification can reduce impersonation within a platform, but it also creates records with consequences beyond the account itself. A password can be reset quickly; a driver’s-license or passport number may remain valid for much longer and can be combined with a name, birth date or facial image.

For people who received a breach notification, the significant point is that one or more records in the affected location contained their information. Identity monitoring can help detect misuse, while a credit freeze may prevent some new accounts from being opened, subject to the procedures and availability in the person’s jurisdiction.

Prospective users face a different choice. Tea does not present an unverified membership route in its current setup, so joining means submitting either live facial data or a selfie-and-ID combination through the available verification process.

The enduring security issue is therefore narrower than whether Tea survived the breach: a service built around safer dating still depends on collecting sensitive verification material. Its public onboarding information shows that collection continues, while leaving several retention and deletion details unavailable to users evaluating the privacy cost.

Also read:

Share:

Subscribe to our newsletter

Get the latest Web3, AI, and crypto news delivered straight to your inbox.

0