/incidents · incident · July 26, 2025

Tea app: 72,000 user images exposed

Source: TechCrunch, July 26, 2025. Written by Lior Aharonov, updated October 3, 2026.

What happened.

On 2025-07-26 TechCrunch reported that Tea, a dating safety app, had been breached and that 72,000 user images were exposed.

Tea said they included about 13,000 selfies and photo IDs submitted for account verification, and 59,000 images from posts, comments and direct messages.

Citing 404 Media, TechCrunch wrote that 4chan users claimed to be sharing the data after discovering an exposed database.

Tea said no emails or phone numbers were exposed, that only users who signed up before February 2024 were affected, and that it had engaged third-party cybersecurity experts.

Why it happens.

The source does not describe the technical cause, so this is the general pattern rather than a finding about Tea. User uploads become public when the storage that holds them allows reads without a signed-in user, or when a bucket is marked public for convenience during development and never closed. Verification documents are often kept long after they are needed, which turns a small mistake into a large one.

How to check yours in five minutes.

  1. List every storage bucket and mark which are public. Only files meant for everyone belong in one.
  2. Open a private file’s direct URL in a private browser window. If it loads without signing in, the bucket is not private.
  3. Find where ID documents or verification photos are stored, and decide how long you keep them.
  4. Read the storage policies: reads of user uploads should require the signed-in owner.
  5. Run the public scan on your app for the headers and exposed files any visitor can see.

Check the public side now.

Ten seconds. We read only what any visitor’s browser already sees, and store nothing.

Opens the app security check on this site with your address filled in.

Source

TechCrunch ↗

Published July 26, 2025. Read it in full; this page summarizes only what it reports.