Security experts uncover Tinder porn site spam scheme
Chatbots use verification offers to lure in victims


Security experts have spotted a Tinder scam that tricks users into signing up for porn site membership in exchange for 'verification'.
The scam, identified by cyber security firm Symantec, uses chatbots to initiate conversations with the dating app's male users. After luring victims in with witty banter, the bots ask them if they are "verified by Tinder".
Note that this is separate to Twitter-style 'blue tick' verification, which Tinder launched last year for celebrities and public figures. Instead, the bots explain that this verification is "a free service tinder put up, to verify the person you wanna meet isn't a serial killer lol".
Victims are directed to an external site, which uses copycat formatting, fonts and logos of Tinder's branding. It promises that after completing the verification form, users will receive a code that they can send to their match for confirmation.
The verification form is, perhaps unsurprisingly, a scam. After providing a user name, password and email, victims must 'verify their age' using a credit card.
The site proudly proclaims that there is "no charge to become verified", but included at the bottom of the page is fine print revealing that unless they specifically uncheck the box, they are opting in to "special FREE bonus offer".
This 'bonus offer' consists of memberships to porn and explicit webcam sites, which have a total value of 118.76. These sites operate on an affiliate model, which means that the scammers receive a cut of the membership fees for every user they bring to it.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Scammers are naturally attracted to large online communities and the surge in online dating amongst millennials makes these sites a prime target," said Nick Shaw, Norton's EMEA vice president and general manager.
"In the online world, as with anything in life, people aren't always what they seem," he said. "Therefore it's important that you are vigilant so you can enjoy dating online without placing yourself in a vulnerable position."
Adam Shepherd has been a technology journalist since 2015, covering everything from cloud storage and security, to smartphones and servers. Over the course of his career, he’s seen the spread of 5G, the growing ubiquity of wireless devices, and the start of the connected revolution. He’s also been to more trade shows and technology conferences than he cares to count.
Adam is an avid follower of the latest hardware innovations, and he is never happier than when tinkering with complex network configurations, or exploring a new Linux distro. He was also previously a co-host on the ITPro Podcast, where he was often found ranting about his love of strange gadgets, his disdain for Windows Mobile, and everything in between.
You can find Adam tweeting about enterprise technology (or more often bad jokes) @AdamShepherUK.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Malicious WordPress plugin installed backdoor on thousands of websites
News Widget plugin spewed spam to unsuspecting victims
By Rene Millman
-
711 million data records revealed in spambot dump
News The data contains email addresses, passwords and server information too
By Zach Marzouk
-
YouPorn and Pornhub activate HTTPS encryption
News Smut sites switch on super-secure encryption to stop state snoopers
By Adam Shepherd
-
Spammers selling fake tickets for Rio Olympics 2016
News Fraudsters have created fake ticketing websites to trick users
By Adam Shepherd
-
PPI companies punished for sending spam texts
News One company was fined £80,000 for sending 1.3 million texts to unsuspecting victims
By Clare Hopping
-
Malware spotted lurking on YouPorn and Pornhub
News Malvertising campaign had 800 million potential victims before being removed
By Joe Curtis
-
Uh-oh - millions of hook-up customers have their details exposed
News But AdultFriendFinder still isn't telling new customers it's been hacked
By Joe Curtis
-
Why restricting porn access opens door to spying
In-depth Tories' election pledge to introduce age restrictions is more worrying than it appears
By Joe Curtis