2026 ShinyHunters breach — 10M+ records (Hinge, Tinder, OkCupid, Match)
Data compromised
User IDs, Hinge subscription data, IP addresses, location data, internal corporate documents, account info
Technical writeup
ShinyHunters compromised Match Group via voice phishing targeting an Okta SSO account. Access to AppsFlyer, Google Drive, and Dropbox. Over 10M records from Hinge, Tinder, OkCupid, and Match exposed. User IDs, subscription data, IP addresses, location data, internal documents. Match Group stated credentials, financial info, and private messages were not accessed.
Root cause
Voice phishing; Okta SSO compromise; phishing domain matchinternal.com
References
- https://www.theregister.com/2026/01/29/shinyhunters_match_group
- https://www.upguard.com/news/match-data-breach-2026-01-29
- https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/
- https://www.acilearning.com/blog/the-biggest-cybersecurity-breaches-of-2026-so-far-and-the-training-that-could-have-prevented-them/
- https://www.pkware.com/blog/2026-data-breaches