Tea app: 72,000 user images exposed
Source: TechCrunch, July 26, 2025. Written by Lior Aharonov, updated October 3, 2026.
What happened.
On 2025-07-26 TechCrunch reported that Tea, a dating safety app, had been breached and that 72,000 user images were exposed.
Tea said they included about 13,000 selfies and photo IDs submitted for account verification, and 59,000 images from posts, comments and direct messages.
Citing 404 Media, TechCrunch wrote that 4chan users claimed to be sharing the data after discovering an exposed database.
Tea said no emails or phone numbers were exposed, that only users who signed up before February 2024 were affected, and that it had engaged third-party cybersecurity experts.
Why it happens.
The source does not describe the technical cause, so this is the general pattern rather than a finding about Tea. User uploads become public when the storage that holds them allows reads without a signed-in user, or when a bucket is marked public for convenience during development and never closed. Verification documents are often kept long after they are needed, which turns a small mistake into a large one.
How to check yours in five minutes.
- List every storage bucket and mark which are public. Only files meant for everyone belong in one.
- Open a private file’s direct URL in a private browser window. If it loads without signing in, the bucket is not private.
- Find where ID documents or verification photos are stored, and decide how long you keep them.
- Read the storage policies: reads of user uploads should require the signed-in owner.
- Run the public scan on your app for the headers and exposed files any visitor can see.
Check the public side now.
Ten seconds. We read only what any visitor’s browser already sees, and store nothing.
Opens the app security check on this site with your address filled in.
TechCrunch ↗
Published July 26, 2025. Read it in full; this page summarizes only what it reports.
How it works, in four steps.
Scan
Check the protections any visitor’s browser can see, then run the deeper scan on an app you prove is yours.
Run the scan → 2 · AuditAI-Build Audit
A signed report within 48 hours: what is exposed, what you own, and the order to fix it in.
Ask for the audit → 3 · FixFix
The report’s list, fixed for a set price by a set date. If we miss the target, the next week is on me.
Ask about the fix → 4 · GuardGuard
A weekly automated scan, dependency and model updates, a monthly senior review, and one named person who answers.
Ask about Guard →