Guides · Updated July 22, 2026
What Was Exposed in the Tea App Data Breach
Tea app data breach: two 2025 exposures, a legacy image store and a separate message database, plus who's affected and what to do next.
If you submitted an ID or selfie to Tea, or wrote private messages you expected to stay private, it is reasonable to want a clear answer. The Tea app data breach involved two reported exposures in late July 2025: a legacy image store containing verification and in-app images, and a separate database containing direct messages. Check which leak may include your account, what Tea has confirmed, and which step fits the information involved.
Check photos and messages separately
If you are worried that your information was included, start by checking the image exposure and message exposure separately. They came from different systems, involved different content, and do not share one clean account-date rule.
| Exposure | Reported contents | Which accounts may be involved | What to ask Tea | What remains unknown |
|---|---|---|---|---|
| Legacy image store | About 13,000 verification selfies or photo-ID images, plus about 59,000 images from posts, comments, and direct messages | Tea said the exposed image dataset related to users who signed up before February 2024 | Did the account exist before that cutoff, and was an ID, selfie, post image, or message image submitted? | Whether a particular file was downloaded, reposted, or misused |
| Separately reported message database | About 1.1 million direct-message records, including sensitive conversations | Reporting described messages from 2023 through the week of the breach | Did the account use direct messages during that period, and has Tea tied the account to this dataset? | Whether every message, conversation, or account was included |
Tea's public statement, reproduced by Simon Willison, described approximately 72,000 images, including about 13,000 selfies and photo identification images. BleepingComputer later reported a separate database containing about 1.1 million private messages. Do not use the February 2024 image cutoff to answer the separate message question.
What is confirmed and what remains open
Reporting linked the first exposure to a legacy Firebase storage bucket and the second to a separately reachable message database. Bitdefender summarized the exposed storage system and separate database reporting. Those reports support the conclusion that there were two separate exposures; they do not answer which individual files an unknown third party accessed.
The files also moved beyond the original discovery. The BBC reported copies on 4chan, maps built from embedded location data, rating sites, and torrents, while NPR described the leak spreading into spaces used to mock or target women. That establishes documented circulation of leaked material in aggregate. It still does not establish that every file or every user's material was reposted.
Tea said it took affected systems offline, disabled direct messaging during the investigation, engaged outside cybersecurity firms, contacted law enforcement, and would notify affected users and offer identity-theft and credit-monitoring services, as summarized in BBC reporting on the response. Security.org's breach review also describes the identity-theft and credit-monitoring offer. For one account, the useful details are which exposure applied, what information was involved, the dates, the assistance offered, and the enrollment deadline.
Treat the totals as file counts, not user counts
The reported numbers describe files or message records, not a one-to-one count of people. One account could have an ID, selfie, and several in-app images; one conversation could contain many messages. The totals do not tell you whether a specific file was copied, whether it circulated publicly, or whether a later event came from the exposure.
Check which leak may include your account
The account date, verification material, message use, and any Tea notice determine which exposure may fit. An unknown answer remains a question for Tea.
| What to check | What you may already know | Why it matters |
|---|---|---|
| Original account-creation date | Welcome email, app-store history, password-manager entry, or Tea support | Helps test Tea's reported pre-February-2024 image boundary |
| Verification material submitted | Original signup memory, saved notice, support response | Separates ID/selfie questions from post or message-image questions |
| Direct-message use and approximate dates | Account history you lawfully retain, notice, support response | Tests possible inclusion in the separately reported message period |
| Email and phone tied to Tea | Password manager, original emails, account settings if still available | Shows where a legitimate notice may arrive and which recovery channel matters |
| Tea notice received | Full email headers, sender domain, support ticket | Tea's response may confirm what was exposed |
An account created after February 2024 does not fit Tea's stated legacy-image window, but that date does not answer the separate message question.
Two examples that change the next step
Early account, ID submitted, no messages. An account created in January 2024 with an ID and selfie fits the reported image window. The unresolved part is whether Tea tied an ID, a selfie, or both to that account.
Later account, messages used. An account created in 2025 may sit outside Tea's stated legacy-image cutoff while still fitting the reported message period. An answer about verification images does not answer whether messages were involved.
Why the kind of exposed information matters
ID image
An ID can connect a legal name, document number, birth date, address, signature, or photo. The concern depends on the document type, which fields were visible, and whether the image can be connected to a public identity.
Verification selfie
A selfie may become more identifying when it is linked to a name, handle, ID, or location. A verification image linked to an identity document reveals a different combination than an ordinary profile photo.
Private messages
The impact depends on what the conversation reveals now. A current home, workplace, school, route, phone number, or recovery email can affect physical or account safety. Health, relationship, abortion, or abuse discussions can create harassment or coercion risk if circulated. A message about another person can also expose someone who may never have had a Tea account.
Account security
Reporting on the image and message exposures did not identify passwords as part of those two datasets. A later phishing or recovery alert is a separate event and does not by itself show that a password came from this breach.
Why linked details can matter more than one file
The practical concern changes when two exposed details can be connected. That does not mean Tea confirmed every combination for every account; it is a way to read the kind of information Tea says was involved and ask a more precise question.
| Details that may be linked | What the link could reveal | What the link may clarify |
|---|---|---|
| ID image and verification selfie | A face connected to a legal identity and document fields | Were both image types tied to this account, and which fields were visible? |
| Selfie and public handle | A private verification image connected to a public profile | Did the exposed copy include a name, handle, location, or other identifier? |
| Message and phone number or email | A private conversation connected to a live contact or recovery channel | Was the contact detail in the message data, an attachment, or somewhere else? |
| Message and current workplace, school, home, or route | Personal context that could make the conversation easier to connect to a person or place | Is the detail still current, and did Tea identify the relevant message period? |
| Message about another person | Private information about someone who may not have had a Tea account | Which part concerns the account holder, and which part concerns another person? |
A single old location may no longer identify where someone lives. A phone number may have changed owners. A message count does not show how many people were discussed. Keep those limits beside the detail instead of treating every possible link as current or confirmed.
Ask Tea one clear question
A useful support request is short:
> Please confirm whether my account was included in the legacy image dataset, the separately reported direct-message database, both, or neither. For each applicable dataset, identify the kind of information and date range, the notice date, the monitoring or identity-protection offer, its enrollment deadline, and the official contact for follow-up.
If Tea cannot answer for your account, that uncertainty should remain explicit rather than being treated as “safe” or “definitely exposed.”
If a direct threat, stalking concern, or immediate physical-safety issue exists, prioritize a safety plan and emergency or local support. Do not wait for a complete account answer.
What to do if you think your Tea app data was exposed
- Check images and messages separately
Record the account date, verification material submitted, direct-message use, and any Tea notice. Do not apply the February 2024 image cutoff to the separate message database.
- Verify any Tea notice through an official channel
Save full email headers or the support ticket, then ask which exposure, kind of information, date range, monitoring offer, and enrollment deadline apply to the account.
- Protect the recovery email and reused credentials
Change reused passwords, enable multi-factor authentication, and preserve targeted login or recovery notices. The reported datasets do not by themselves prove that passwords were exposed.
- Take the steps that match the exposed data
Enroll in Tea's offered monitoring if eligible; ask the ID issuer for document-specific guidance; submit a removal request to the image host; secure an affected recovery account; and share only the minimum necessary detail with a person or support service affected by an exposed message.
- Document copies, misuse, and follow-up minimally
Save the stable URL, host, date, account name, and one contextual screenshot before requesting removal. Keep any fraud, impersonation, threat, recovery, or support case number with its response. Do not download or redistribute an archive; use a lawyer or local support service for situation-specific legal or immediate-safety guidance.
- Apply the lesson to future dating checks
Before giving another service identity documents, review its collection, retention, access, and deletion terms. For future dating decisions, use TheTeaReport to keep the lookup private instead of posting identities to a shared social feed. Results can still be incomplete or mismatched and cannot establish that someone is trustworthy.
Sources and further reading
Stop guessing. Start vetting.
Criminal records, marriage history, and sex-offender registry checks. All the tea you deserve before you invest your time, energy, and trust.