Guides · Updated July 22, 2026

What Was Exposed in the Tea App Data Breach

Tea app data breach: two 2025 exposures, a legacy image store and a separate message database, plus who's affected and what to do next.

If you submitted an ID or selfie to Tea, or wrote private messages you expected to stay private, it is reasonable to want a clear answer. The Tea app data breach involved two reported exposures in late July 2025: a legacy image store containing verification and in-app images, and a separate database containing direct messages. Check which leak may include your account, what Tea has confirmed, and which step fits the information involved.

Check photos and messages separately

If you are worried that your information was included, start by checking the image exposure and message exposure separately. They came from different systems, involved different content, and do not share one clean account-date rule.

ExposureReported contentsWhich accounts may be involvedWhat to ask TeaWhat remains unknown
Legacy image storeAbout 13,000 verification selfies or photo-ID images, plus about 59,000 images from posts, comments, and direct messagesTea said the exposed image dataset related to users who signed up before February 2024Did the account exist before that cutoff, and was an ID, selfie, post image, or message image submitted?Whether a particular file was downloaded, reposted, or misused
Separately reported message databaseAbout 1.1 million direct-message records, including sensitive conversationsReporting described messages from 2023 through the week of the breachDid the account use direct messages during that period, and has Tea tied the account to this dataset?Whether every message, conversation, or account was included

Tea's public statement, reproduced by Simon Willison, described approximately 72,000 images, including about 13,000 selfies and photo identification images. BleepingComputer later reported a separate database containing about 1.1 million private messages. Do not use the February 2024 image cutoff to answer the separate message question.

What is confirmed and what remains open

Reporting linked the first exposure to a legacy Firebase storage bucket and the second to a separately reachable message database. Bitdefender summarized the exposed storage system and separate database reporting. Those reports support the conclusion that there were two separate exposures; they do not answer which individual files an unknown third party accessed.

The files also moved beyond the original discovery. The BBC reported copies on 4chan, maps built from embedded location data, rating sites, and torrents, while NPR described the leak spreading into spaces used to mock or target women. That establishes documented circulation of leaked material in aggregate. It still does not establish that every file or every user's material was reposted.

Tea said it took affected systems offline, disabled direct messaging during the investigation, engaged outside cybersecurity firms, contacted law enforcement, and would notify affected users and offer identity-theft and credit-monitoring services, as summarized in BBC reporting on the response. Security.org's breach review also describes the identity-theft and credit-monitoring offer. For one account, the useful details are which exposure applied, what information was involved, the dates, the assistance offered, and the enrollment deadline.

Treat the totals as file counts, not user counts

The reported numbers describe files or message records, not a one-to-one count of people. One account could have an ID, selfie, and several in-app images; one conversation could contain many messages. The totals do not tell you whether a specific file was copied, whether it circulated publicly, or whether a later event came from the exposure.

Check which leak may include your account

The account date, verification material, message use, and any Tea notice determine which exposure may fit. An unknown answer remains a question for Tea.

What to checkWhat you may already knowWhy it matters
Original account-creation dateWelcome email, app-store history, password-manager entry, or Tea supportHelps test Tea's reported pre-February-2024 image boundary
Verification material submittedOriginal signup memory, saved notice, support responseSeparates ID/selfie questions from post or message-image questions
Direct-message use and approximate datesAccount history you lawfully retain, notice, support responseTests possible inclusion in the separately reported message period
Email and phone tied to TeaPassword manager, original emails, account settings if still availableShows where a legitimate notice may arrive and which recovery channel matters
Tea notice receivedFull email headers, sender domain, support ticketTea's response may confirm what was exposed

An account created after February 2024 does not fit Tea's stated legacy-image window, but that date does not answer the separate message question.

Two examples that change the next step

Early account, ID submitted, no messages. An account created in January 2024 with an ID and selfie fits the reported image window. The unresolved part is whether Tea tied an ID, a selfie, or both to that account.

Later account, messages used. An account created in 2025 may sit outside Tea's stated legacy-image cutoff while still fitting the reported message period. An answer about verification images does not answer whether messages were involved.

Why the kind of exposed information matters

ID image

An ID can connect a legal name, document number, birth date, address, signature, or photo. The concern depends on the document type, which fields were visible, and whether the image can be connected to a public identity.

Verification selfie

A selfie may become more identifying when it is linked to a name, handle, ID, or location. A verification image linked to an identity document reveals a different combination than an ordinary profile photo.

Private messages

The impact depends on what the conversation reveals now. A current home, workplace, school, route, phone number, or recovery email can affect physical or account safety. Health, relationship, abortion, or abuse discussions can create harassment or coercion risk if circulated. A message about another person can also expose someone who may never have had a Tea account.

Account security

Reporting on the image and message exposures did not identify passwords as part of those two datasets. A later phishing or recovery alert is a separate event and does not by itself show that a password came from this breach.

Why linked details can matter more than one file

The practical concern changes when two exposed details can be connected. That does not mean Tea confirmed every combination for every account; it is a way to read the kind of information Tea says was involved and ask a more precise question.

Details that may be linkedWhat the link could revealWhat the link may clarify
ID image and verification selfieA face connected to a legal identity and document fieldsWere both image types tied to this account, and which fields were visible?
Selfie and public handleA private verification image connected to a public profileDid the exposed copy include a name, handle, location, or other identifier?
Message and phone number or emailA private conversation connected to a live contact or recovery channelWas the contact detail in the message data, an attachment, or somewhere else?
Message and current workplace, school, home, or routePersonal context that could make the conversation easier to connect to a person or placeIs the detail still current, and did Tea identify the relevant message period?
Message about another personPrivate information about someone who may not have had a Tea accountWhich part concerns the account holder, and which part concerns another person?

A single old location may no longer identify where someone lives. A phone number may have changed owners. A message count does not show how many people were discussed. Keep those limits beside the detail instead of treating every possible link as current or confirmed.

Ask Tea one clear question

A useful support request is short:

> Please confirm whether my account was included in the legacy image dataset, the separately reported direct-message database, both, or neither. For each applicable dataset, identify the kind of information and date range, the notice date, the monitoring or identity-protection offer, its enrollment deadline, and the official contact for follow-up.

If Tea cannot answer for your account, that uncertainty should remain explicit rather than being treated as “safe” or “definitely exposed.”

If a direct threat, stalking concern, or immediate physical-safety issue exists, prioritize a safety plan and emergency or local support. Do not wait for a complete account answer.

What to do if you think your Tea app data was exposed

  1. Check images and messages separately

    Record the account date, verification material submitted, direct-message use, and any Tea notice. Do not apply the February 2024 image cutoff to the separate message database.

  2. Verify any Tea notice through an official channel

    Save full email headers or the support ticket, then ask which exposure, kind of information, date range, monitoring offer, and enrollment deadline apply to the account.

  3. Protect the recovery email and reused credentials

    Change reused passwords, enable multi-factor authentication, and preserve targeted login or recovery notices. The reported datasets do not by themselves prove that passwords were exposed.

  4. Take the steps that match the exposed data

    Enroll in Tea's offered monitoring if eligible; ask the ID issuer for document-specific guidance; submit a removal request to the image host; secure an affected recovery account; and share only the minimum necessary detail with a person or support service affected by an exposed message.

  5. Document copies, misuse, and follow-up minimally

    Save the stable URL, host, date, account name, and one contextual screenshot before requesting removal. Keep any fraud, impersonation, threat, recovery, or support case number with its response. Do not download or redistribute an archive; use a lawyer or local support service for situation-specific legal or immediate-safety guidance.

  6. Apply the lesson to future dating checks

    Before giving another service identity documents, review its collection, retention, access, and deletion terms. For future dating decisions, use TheTeaReport to keep the lookup private instead of posting identities to a shared social feed. Results can still be incomplete or mismatched and cannot establish that someone is trustworthy.

Sources and further reading

Stop guessing. Start vetting.

Criminal records, marriage history, and sex-offender registry checks. All the tea you deserve before you invest your time, energy, and trust.

Start a private background report

Related guides