Niche dating apps expose almost 1TB of user data
Sensitive material, including images and voice recordings, has been exposed due to a misconfigured AWS S3 bucket
 
 
More than 20 million files owned by several dating apps were recently exposed, leaking sensitive information ranging from explicit media to the entire infrastructures of the apps.
Approximately 845GB of user and app data was leaked through a single misconfigured AWS account hosting data from a wide selection of niche dating apps, including Cougary, Xpal and CasualX, among others.
The “incredibly sensitive” files included media such as images and audio recordings, as well as private message exchanges, and evidence of financial transactions. The breach also exposed the various apps’ entire AWS infrastructure through unsecured admin credentials and passwords.
This leak affected at least 100,000 users, although it could potentially affect millions, according to researchers with vpnMentor, who stumbled on the database as part of a huge web-mapping project.
The S3 buckets contained limited personally identifiable information (PII), although many of the files directly or indirectly exposed individuals as they included photos with visible faces, user names and financial data.
“Our team was able to access this bucket because it was completely unsecured and unencrypted,” vpnMentor said in a post.
“As ethical hackers, we’re obliged to inform a company when we discover flaws in their online security. We reached out to the developers, not only to let them know about the vulnerability but also to suggest ways in which they could make their system secure.”
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The research team added it’s important to note that publicly accessible S3 buckets are not a flaw of AWS, and usually arise as a result of an error by the owner of the bucket.
In cases such as that of these dating apps, the easiest remedy would be to make the bucket private and add authentication protocols, follow AWS access and authentication best practices, and add further layers of protection to S3 buckets to restrict who can access it from every point of entry.
The research team reached out to the owner of one of the apps, 3somes, on 24 May to present its findings. The developer responded asking for additional details, after which point vpnMentor offered the URL of the misconfigured bucket and mentioned the other buckets owned by apparent sister companies were open too.
Although there was no further communication, on 27 May the S3 buckets belonging to every other app were re-secured, confirming vpnMentor’s assumption that all the services shared a common developer.
“Using the images from various apps, hackers could create effective fake profiles for catfishing schemes, to defraud and abuse unwary users,” the vpnMentor post continued.
“Given the nature of many of these apps – in some cases involving financial transactions, fetishes, and STIs – having your presence on the app made public could create immense stress in your personal life.”
The research team has previously discovered a string of leaked databases in the past few months and years. For example, vpnMentor found that millions of text messages leaked through an exposed TrueDialog server in December 2019.
More recently, a huge leak exposed a wealth of personal and financial data held by British consultancy firms in January, as well as thousands of professionals, ranging from expenses forms to personal names and addresses.

Keumars Afifi-Sabet is a writer and editor that specialises in public sector, cyber security, and cloud computing. He first joined ITPro as a staff writer in April 2018 and eventually became its Features Editor. Although a regular contributor to other tech sites in the past, these days you will find Keumars on LiveScience, where he runs its Technology section.
- 
 Manufacturers report millions in losses as downtime wreaks havoc on operations Manufacturers report millions in losses as downtime wreaks havoc on operationsNews UK manufacturers are losing up to £736 million every week due to downtime, according to new research, with outages lasting for several days on end. 
- 
 Microsoft gives OpenAI restructuring plans the green light Microsoft gives OpenAI restructuring plans the green lightNews The deal removes fundraising constraints and modifies Microsoft's rights to use OpenAI models and products 
- 
 Dell Technologies World 2022: Dell unveils security offerings for major cloud providers Dell Technologies World 2022: Dell unveils security offerings for major cloud providersNews The tech giant also added Cyber Recovery Services to its existing Apex portfolio and announced a multi-cloud collaboration with Snowflake Data Cloud 
- 
 Denonia named as first malware to target AWS Lambda platform Denonia named as first malware to target AWS Lambda platformNews Deployment demonstrates how attackers are using advanced cloud-specific knowledge to exploit complex cloud infrastructure, Cado Security says 
- 
 MWC 2022: Ukrainian protesters call for Russian tech boycott MWC 2022: Ukrainian protesters call for Russian tech boycottNews The protestors are urging AWS to “shut down” servers being used by Russian entities 
- 
 AWS' CodeGuru Reviewer updated to tackle Log4j AWS' CodeGuru Reviewer updated to tackle Log4jNews Amazon's code reviewer also now includes a library detailing every detector used by the platform 
- 
 Sennheiser exposed personal data of 28,000 customers with leaky S3 bucket Sennheiser exposed personal data of 28,000 customers with leaky S3 bucketNews Server containing full names, email addresses, phone numbers, and supplier information was left open to the public for three years 
- 
 AWS shuts down NSO Group infrastructure AWS shuts down NSO Group infrastructureNews The Israeli company’s Pegasus spyware was used to target at least 50,000 mobile phones 
- 
 AWS Network Firewall provides network protection across all workloads AWS Network Firewall provides network protection across all workloadsNews New firewall tools offer improved security in virtual private clouds 
- 
 EU charges Amazon over misuse of third-party data EU charges Amazon over misuse of third-party dataNews The EC claims Amazon broke competition rules by using data gathered on third-party sellers to compete against them