Unverified claim — July 2026: Threat-intelligence channels flagged a cybercrime-forum listing advertising an alleged database tied to Badoo, the global dating platform owned by Bumble Inc., citing roughly 51 million user records. Badoo had not confirmed any matching incident at indexing time.
What is being claimed
Forum sellers routinely market dating-app dumps because the data powers romance scams, credential stuffing, and blackmail. The July 2026 Badoo listing follows that pattern: a named consumer brand, a nine-figure row count, and no accompanying company FAQ.
This is separate from Badoo's older verified loads on Have I Been Pwned from 2013 and 2016. A fresh 51M-row advertisement could mean a new exfiltration, a repackaged older corpus, or outright bluffing — forum posts alone cannot tell which.
Why dating-app dumps hurt even without passwords
Even when listings emphasize emails and profile metadata, dating platforms sit on photos, locations, age ranges, and match history that attackers use for sextortion and impersonation. If you ever paid for Badoo premium, billing-adjacent phishing is another follow-on.
What is not confirmed
- No Badoo customer email or in-app notice matching the forum timeline
- No independently authenticated sample set reviewed by major trade press at catalog time
- Field-level contents of the advertised 51M rows
Action items for Badoo users
- Change your Badoo password and enable two-factor authentication if available.
- Do not download alleged leak files from forums or Telegram.
- Be wary of “verify your profile” or “someone liked you” messages with login links.
- Check HIBP for your email across all breaches, not just this claim.
Canonical record: Badoo 2026 forum claim on BreachHistory — indexed as unverified.