Back Escudodigital 15 million Grindr users' data put up for sale on dark web
The alleged leak includes full names, email addresses, physical attributes, and HIV status details from the LGBTQ+ dating app.
A threat actor has posted a message on a dark web forum claiming to be selling a complete database of users that, according to their version, belongs to the dating app for homosexuals, Grindr .
The allegedly compromised dataset would include more than 15 million records associated with accounts on the platform .
The hacker boasts of having details such as i dentifiers, first and last names, email addresses, and verification statuses. Password hashes, OAuth-related data, and in some cases technical information like IP addresses, device type, and user agent are also mentioned.
To make matters worse, the hacker also claims to have exfiltrated especially sensitive details, such as information related to sexual orientation, gender, and date of birth, as well as physical attributes declared within the app. There is also reference to location data that would include city, country, and even precise geographic coordinates.
It is also noteworthy that the cybercriminal has managed to obtain i nformation related to HIV and dates of the latest tests.
For now, the data breach has not been confirmed by third parties . At the time of writing this news, Grindr Inc had also not publicly commented on this information.
The cybercriminal, who goes by the nickname 'nilojeda', is selling this pack at a ridiculously low price (only $400) , which can be paid in various cryptocurrencies. This rate would make more sense if it is not an offer for the highest bidder, but rather marketed to multiple interested parties.
A threat actor has posted a message on a dark web forum claiming to be selling a complete database of users that, according to their version, belongs to the dating app for homosexuals, Grindr .
The allegedly compromised dataset would include more than 15 million records associated with accounts on the platform .
The hacker boasts of having details such as i dentifiers, first and last names, email addresses, and verification statuses. Password hashes, OAuth-related data, and in some cases technical information like IP addresses, device type, and user agent are also mentioned.
To make matters worse, the hacker also claims to have exfiltrated especially sensitive details, such as information related to sexual orientation, gender, and date of birth, as well as physical attributes declared within the app. There is also reference to location data that would include city, country, and even precise geographic coordinates.
It is also noteworthy that the cybercriminal has managed to obtain i nformation related to HIV and dates of the latest tests.
For now, the data breach has not been confirmed by third parties . At the time of writing this news, Grindr Inc had also not publicly commented on this information.
The cybercriminal, who goes by the nickname 'nilojeda', is selling this pack at a ridiculously low price (only $400) , which can be paid in various cryptocurrencies. This rate would make more sense if it is not an offer for the highest bidder, but rather marketed to multiple interested parties.
Become a premium member for free!
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
