Another Day, Another Dating App Leaking Your ID

TeaOnHer, the men's counterpart to the women's safety app Tea, is hemorrhaging user data faster than you can swipe left. TechCrunch discovered that anyone can access the app's database containing driver's licenses, selfies, email addresses, and usernames of all 53,000 users.

No hacking required. The data is just sitting there on public URLs, waiting for someone to stumble across it.

But here's the really embarrassing part: the app's creator, Xavier Lampkin, left his own admin credentials exposed on the server. Email address and plaintext password, just hanging out in the open. It's like leaving your house keys taped to the front door with a note saying "please don't rob me."

This is What Happens When You Build Apps Out of Spite

TeaOnHer launched this week as a direct response to Tea, the controversial women's app that lets users share warnings about men they've dated. Tea got breached last week, exposing 72,000 images and over a million private messages. Instead of learning from that disaster, someone thought "let's build the exact same thing but for men."

The results are predictably awful. TeaOnHer users upload government IDs for verification, then post photos and accusations about women they claim to have dated. The guest view (no signup required) immediately shows naked photos of the same woman posted under different names, plus comments calling women "easy" or accusing of spreading STIs.

It's revenge porn with extra steps and worse security.

Basic Security Concepts That Apparently Don't Exist

The technical details are mind-numbing in their incompetence:

  • Direct URL access to driver's licenses: Upload an ID to verify your account? It goes on a public web address that anyone can guess or stumble across
  • Exposed user database: All 53,000 user emails, usernames, and locations are accessible without authentication
  • Admin credentials in plaintext: The founder's login details are sitting on the public server
  • No access controls: Guest users can see everything without even creating an account

This isn't a sophisticated attack or zero-day exploit. This is basic web development that a bootcamp student would be embarrassed to submit. You literally just need to know how URLs work to access people's government IDs.

The Creator Left His Own Data Exposed

Xavier Lampkin, founder of Newville Media Corporation and creator of TeaOnHer, apparently didn't test his own security. TechCrunch found his personal data in the exposed database, along with his admin credentials sitting on the server in plaintext.

When TechCrunch tried to contact Lampkin about the security flaws, he didn't respond. The app is currently ranked #2 in Lifestyle apps on iOS and #17 overall, beating Instagram, Netflix, and Spotify. Thousands of people are downloading an app that immediately exposes their driver's license to the internet.

Why Dating Apps Keep Failing at Basic Security

This is becoming a pattern. Tea gets breached, TeaOnHer gets breached, Bumble had location tracking issues, Tinder leaked swipe data. Dating apps collect incredibly sensitive information – photos, locations, personal details, sometimes government IDs – but treat security like an afterthought.

Part of the problem is that dating apps are often built by small teams focused on user acquisition, not security. They're optimizing for viral growth and App Store rankings, not protecting user data. Basic security features like access controls, encrypted storage, and secure API endpoints cost time and money that startups don't want to spend.

The other issue is that users keep downloading these apps despite repeated security failures. TeaOnHer is trending on the App Store even though it's obviously unsafe to use. People are more concerned with getting their revenge posts live than protecting their driver's license from random internet strangers.

What You Need to Know Right Now

If you downloaded TeaOnHer and uploaded an ID for verification, assume that document is now publicly accessible on the internet. Anyone with basic technical skills can find and download your driver's license, along with your email address and any selfies you uploaded.

The app makers haven't acknowledged the security flaws or announced any fixes. TechCrunch is withholding technical details to avoid helping malicious actors, but the vulnerabilities they found are apparently simple to exploit.

Delete the app if you have it installed. Don't upload government documents to apps built by companies you've never heard of. And maybe consider whether posting revenge content about your exes is worth risking identity theft.

FAQ: TeaOnHer Data Breach Disaster

Q

How bad is this breach?

A

Catastrophic. 53,000 users' driver's licenses, selfies, emails, and usernames are publicly accessible. No hacking required – just visit the right URL and download someone's government ID.

Q

I uploaded my ID to TeaOnHer. What should I do?

A

Assume your driver's license is now publicly available on the internet. Monitor your credit reports, consider identity theft protection, and maybe get a new ID if your state allows it.

Q

How is this different from the Tea app breach?

A

Tea got hacked by 4chan users who found an exposed database. TeaOnHer just leaves everything in the open by design. Their "security" is basically non-existent.

Q

Who's responsible for this mess?

A

Xavier Lampkin, founder of Newville Media Corporation. He built an app that immediately exposes user data, then left his own admin credentials on the public server.

Q

Can I sue over this?

A

Probably. Exposing government IDs through basic security negligence violates multiple privacy laws. Expect class-action lawsuits within weeks.

Q

Why didn't app stores catch this?

A

Apple and Google's review processes focus on content and functionality, not security audits. They don't test whether apps leak user data to the internet.

Q

Is my data safe if I delete the app now?

A

No. If you already uploaded an ID, it's still sitting on their servers at a public URL. Deleting the app from your phone doesn't remove your data from their database.

Q

How do dating apps keep screwing up security this badly?

A

Small teams, tight budgets, focus on growth over security. They're optimizing for App Store rankings, not protecting sensitive data. Basic security costs time and money they don't want to spend.

Q

Should I trust any dating app with my ID?

A

Hell no. Don't upload government documents to apps built by startups you've never heard of. Even established companies regularly leak user data.

Related Tools & Recommendations

news
Similar content

VPN Security Exposed: Are Your 'Secure' VPNs Truly Safe?

Millions of users thought they were protected. They were wrong.

/news/2025-09-02/vpn-security-vulnerabilities
94%
news
Similar content

Passkeys Hacked at DEF CON: Are Passwordless Futures Broken?

The password replacement that was supposed to save us got owned at DEF CON

/news/2025-09-02/passkey-vulnerability-defcon
79%
news
Similar content

DeepSeek Database Breach Exposes 1 Million AI Chat Logs

DeepSeek's database exposure revealed 1 million user chat logs, highlighting a critical gap between AI innovation and fundamental security practices. Learn how

General Technology News
/news/2025-01-29/deepseek-database-breach
79%
news
Similar content

eSIM Flaw Exposes 2 Billion Devices to SIM Hijacking

NITDA warns Nigerian users as Kigen vulnerability allows remote device takeover through embedded SIM cards

Technology News Aggregation
/news/2025-08-25/esim-vulnerability-kigen
79%
news
Similar content

AI Generates CVE Exploits in Minutes: Cybersecurity News

Revolutionary cybersecurity research demonstrates automated exploit creation at unprecedented speed and scale

GitHub Copilot
/news/2025-08-22/ai-exploit-generation
76%
news
Similar content

Tech News Overview: Google AI, NVIDIA Robotics, Ad Blockers & Apple Zero-Day

Breaking AI accessibility barriers with multilingual video summaries and enhanced audio overviews

Technology News Aggregation
/news/overview
76%
news
Similar content

vtenext CRM Allows Unauthenticated Remote Code Execution

Three critical vulnerabilities enable complete system compromise in enterprise CRM platform

Technology News Aggregation
/news/2025-08-25/vtenext-crm-triple-rce
73%
news
Similar content

vtenext CRM Zero-Day: Triple Vulnerabilities Expose SMBs

Three unpatched flaws allow remote code execution on popular business CRM used by thousands of companies

Technology News Aggregation
/news/2025-08-25/apple-zero-day-rce-vulnerability
73%
news
Similar content

Grok Privacy Disaster: xAI Exposes 370K Private Chats Publicly

Documents, photos, and conversations searchable on Google because someone fucked up the share button - August 24, 2025

General Technology News
/news/2025-08-24/grok-privacy-disaster
73%
news
Similar content

Tenable Appoints Matthew Brown as CFO Amid Market Growth

Matthew Brown appointed CFO as exposure management company restructures C-suite amid growing enterprise demand

Technology News Aggregation
/news/2025-08-24/tenable-cfo-appointment
70%
news
Similar content

Apple ImageIO Zero-Day CVE-2025-43300: Patch Your iPhone Now

Another zero-day in image parsing that someone's already using to pwn iPhones - patch your shit now

GitHub Copilot
/news/2025-08-22/apple-zero-day-cve-2025-43300
70%
news
Similar content

Anthropic Claude Data Policy Changes: Opt-Out by Sept 28 Deadline

September 28 Deadline to Stop Claude From Reading Your Shit - August 28, 2025

NVIDIA AI Chips
/news/2025-08-28/anthropic-claude-data-policy-changes
70%
news
Similar content

Apple Sues Ex-Engineer for Apple Watch Secrets Theft to Oppo

Dr. Chen Shi downloaded 63 confidential docs and googled "how to wipe out macbook" because he's a criminal mastermind - August 24, 2025

General Technology News
/news/2025-08-24/apple-oppo-lawsuit
70%
news
Similar content

El Salvador Moves Bitcoin Treasury to Escape Quantum Threats

El Salvador takes unprecedented steps to protect its national Bitcoin treasury from future quantum computing threats. Learn how the nation is preparing for the

Samsung Galaxy Devices
/news/2025-08-31/el-salvador-quantum-bitcoin
70%
news
Similar content

Samsung Knox: Third Diamond Security Rating for Smart Home Dominance

Samsung Knox Defense-Grade Security Platform

NVIDIA AI Chips
/news/2025-08-29/samsung-knox-diamond-security
70%
news
Similar content

Creem Fintech Raises €1.8M for AI Startups & Financial OS

Ten-month-old company hits $1M ARR without a sales team, now wants to be the financial OS for AI-native companies

Technology News Aggregation
/news/2025-08-25/creem-fintech-ai-funding
70%
news
Similar content

Verizon Outage: Service Restored After Nationwide Glitch

Software Glitch Leaves Thousands in SOS Mode Across United States

OpenAI ChatGPT/GPT Models
/news/2025-09-01/verizon-nationwide-outage
67%
news
Similar content

Wallarm Report: 639 API Vulnerabilities in AI Systems Q2 2025

Security firm reveals 34 AI-specific API flaws as attackers target machine learning models and agent frameworks with logic-layer exploits

Technology News Aggregation
/news/2025-08-25/wallarm-api-vulnerabilities
64%
news
Similar content

Docker Desktop CVE-2025-9074: Critical Container Escape Vulnerability

A critical vulnerability (CVE-2025-9074) in Docker Desktop versions before 4.44.3 allows container escapes via an exposed Docker Engine API. Learn how to protec

Technology News Aggregation
/news/2025-08-26/docker-cve-security
64%
news
Similar content

Git RCE Vulnerability Exploited: CVE-2025-48384 Under Attack

CVE-2025-48384 lets attackers execute code just by cloning malicious repos - CISA added it to the actively exploited list today

Technology News Aggregation
/news/2025-08-26/git-cve-rce-exploit
64%

Recommendations combine user behavior, content similarity, research intelligence, and SEO optimization