TEA APP▊
Organization dossier Tea Dating Advice, Inc. Status: still operating
A women’s-safety app that demanded a selfie and a driver’s license to prove you were real — then left roughly 72,000 of those images, about 13,000 of them selfies and photo IDs, sitting in a storage bucket with no password on it. 4chan found it before the company did. The app whose entire pitch was “verify, so you’re safe” became the reason its users were not.
This data was originally stored in compliance with law enforcement requirements related to cyber-bullying prevention.
Tea Dating Advice spokesperson, on the breached legacy archive, as quoted by NBC News (Jul 2025)
Protecting our users’ privacy and data is our highest priority. Tea is taking every necessary step to ensure the security of our platform and prevent further exposure.
Tea Dating Advice spokesperson, breach statement, per NBC News (Jul 2025)
- ENTITY
- Tea Dating Advice, Inc., San Francisco — maker of “Tea,” a women-only dating-safety app (a “whisper network” for warning about men) FACT
- FOUNDER
- Sean Cook, software engineer — the documented operator and public face; the record below is the company’s security posture, not a personal indictment FACT
- THE PROMISE
- To join, users submitted a selfie — and, for verification, a photo ID / driver’s license — to prove they were women. Anonymity and safety were the pitch. FACT
- THE BREACH
- An exposed Google Firebase storage bucket, no authentication, left ~72,000 images public (~13,000 selfies + photo IDs). A second flaw exposed ~1.1M direct messages. Found and spread on 4chan. FACT
- THE RECORD
- No fault has been adjudicated. The exposed bucket and the ID leak are documented fact; at least ten lawsuits are pending, unproven. The “safety app that doxxed its own users” line is framing, attributed. ATTRIBUTED
- STATUS
- STILL OPERATING — the app remains live; direct messaging was taken offline; identity-protection services were offered to affected users
This one is a company, not a person — and the drama is not a scandal of character but of engineering. An app sold safety. Safety, here, meant collecting the most sensitive document a person owns: a government photo ID. The company gathered those documents by the thousand — and then, on the record, stored a legacy pile of them where anyone with a browser could take them.
What follows is the sequence in order: the premise, the exposed bucket, the second hole, the statements, the lawsuits. Every beat carries its receipt. The mechanism — how the images got out — gets its own beat, because the how is the whole story. Both sides get the microphone. You decide.
the drama timeline
ACT I — THE PREMISE (2023–JUL 2025)
Before the leak, the pitch. An app for women to vet men — and to use it, you first had to prove you were a woman. The proof was a selfie and, for verification, a photo ID. The safety model was built on collecting exactly the data that would later escape.
-
2023
The safety app, and the ID it demanded
Tea Dating Advice, Inc., founded by software engineer Sean Cook, launches Tea — a women-only app that lets users post about and search men by name, flagging them “red flag” or “green flag.” Signing up requires a selfie to prove the user is a woman; verification could require a photo ID. Users are promised anonymity; screenshots inside the app are blocked. The premise is safety through verification.
-
JUL 2025
Viral — and a target
Tea briefly becomes the top free app in the Apple App Store. Its popularity draws a backlash; on the evening of Thursday, July 24, a thread on 4chan calls for a “hack and leak” campaign against it.
The materials were already gathered: tens of thousands of government IDs, sitting in storage. All the display needed was an audience that knew where to look.
ACT II — THE EXPOSED BUCKET (JUL 24–25, 2025)
Here is the mechanism, stated plainly, because the mechanism is the case. Not a sophisticated intrusion. Not a cracked password. A storage bucket left open to the public internet, holding the one document the app had told users to trust it with.
-
JUL 24–25, 2025
HOW IT HAPPENED — the open Firebase bucket
The exposed data sat in a Google Firebase storage bucket left publicly accessible — with no authentication of any kind. As the source who found it described the configuration to 404 Media: “No authentication, no nothing. It’s a public bucket.” Inside were roughly 72,000 images, including about 13,000 selfies and photo IDs — driver’s licenses among them — submitted for verification, plus tens of thousands of images from posts, comments, and messages. Anyone with the address could download them. There was no lock to pick.
The safety app’s security failure was not that its walls were breached. It was that the vault holding the driver’s licenses had no door.
-
JUL 25, 2025
Found on 4chan; the company detects it the same morning
A 4chan user posts a link on Friday morning offering the trove of images; alleged victims’ ID photos are reposted across 4chan and X. The company says it became aware of the incident early that Friday. 404 Media, the first outlet to report it, breaks the story. (This archive does not reproduce or link any leaked data.)
ACT III — THE SECOND HOLE (JUL 28–29, 2025)
One open bucket would have been the whole story. Then a researcher looked at the messaging system and found the door there was unlocked too — a different mechanism, the same result.
-
JUL 28–29, 2025
1.1 million direct messages, reachable by any user’s own key
Security researcher Kasra Rahjerdi reports a second flaw: any Tea user could reach the platform’s stored data using their own API key, exposing more than 1.1 million direct messages spanning 2023 to mid-2025 — intimate, identifying conversations. Rahjerdi told NBC News he could see that others had previously accessed the database. Tea takes the affected system offline and disables direct messaging.
ACT IV — THE RECKONING (JUL–AUG 2025)
The company answered on the record — a legacy system, experts engaged, protection offered. Then the plaintiffs answered too.
-
JUL 2025
The company’s statement
Tea confirms the breach and frames the exposed archive as a legacy dataset predating February 2024. Its spokesperson says the company has engaged third-party cybersecurity experts and is “working around the clock to secure our systems,” that “no email addresses or phone numbers were accessed,” and that it is identifying affected users and offering free identity-protection services. On the messages, the company says it “recently learned that some direct messages (DMs) were accessed as part of the initial incident” and that, “out of an abundance of caution, we have taken the affected system offline.”
-
AUG 2025
The lawsuits
At least ten women file suit against Tea over the exposure of their photos and data; by early August, ten class-action complaints are reported. The suits allege the company failed to protect the data it required; the allegations are unproven and no court has ruled. Litigation is pending.
-
EPILOGUE
Still operating
The app remains live. Direct messaging stayed offline in the aftermath; identity-protection services were offered. The IDs, once out, do not come back. The archive keeps the record; it does not keep the images.
both sides, on the record
The documented failure: the exposed data sat in a Google Firebase storage bucket that was publicly accessible with no authentication — “a public bucket,” per the source who found it — leaving roughly 72,000 images public, about 13,000 of them selfies and photo IDs including driver’s licenses [1] [2]. This is not an allegation; it is the confirmed configuration.
Then a second hole: a separate flaw let any user reach stored data with their own API key, exposing more than 1.1 million private messages [3] [4].
The framing (attributed, not ours): commentators have called it “the safety app that doxxed its own users” — the app that required a government ID to keep women safe became the reason those IDs are on 4chan. Stated as the characterization it is; the facts under it are documented [1] [6].
The company’s position, in its own words: the breached data was a legacy archive predating February 2024, originally stored “in compliance with law enforcement requirements related to cyber-bullying prevention”; no email addresses or phone numbers were accessed; the company engaged third-party cybersecurity experts, took the affected system offline “out of an abundance of caution,” and offered free identity-protection services to affected users [2] [5].
The stated mission: Tea was built as a safety tool for women — a whisper network to warn each other about dangerous men — and the ID requirement existed to keep the network women-only [2].
The wrongdoers are the attackers: the data was located and spread by hostile actors — a 4chan “hack and leak” campaign — who bear responsibility for exfiltrating and republishing it. Nothing on this record is an adjudication of the company’s liability; the lawsuits are pending and their allegations are unproven [2] [6].
YOU DECIDE
Scoped to the claims, never re-victimizing the users. The claim “the data was exposed by a security failure” is not in dispute: the images sat in a storage bucket open to the public internet with no authentication, and the company confirmed the count. The claim “Tea failed its users” is what ten pending lawsuits will test — unproven, unadjudicated, and stated here as pending. The company’s defense — legacy system, no emails or phones taken, experts engaged, protection offered, attackers to blame for the spread — stays on this page at full strength.
Weigh the costly signal. An app can ask for a driver’s license or it can promise safety; asking for one is a promise to protect it. The document was collected. The lock was, per the record, never installed. Whatever a court decides about fault, that gap is the case.
The archive does not judge. The archive keeps the record — and never the leaked data.
evidence locker
PRIMARY REPORTING — THE BREACH
404 Media — “Women Dating Safety App ‘Tea’ Breached, Users’ IDs Posted to 4chan” (Jul 25, 2025) FACT — the original report; the exposed Firebase bucket described as “a public bucket… no authentication.”
404media.co/women-dating-safety-app-tea-breached-…
NBC News — “Tea app hacked: 13,000 photos leaked after 4chan call to action” (Jul 2025) FACT — the 72,000 / 13,000 figures, the app’s design, the 4chan thread, and Tea’s verbatim statement.
nbcnews.com/tech/social-media/…-rcna221139
THE COMPANY, ON THE RECORD
Tea Dating Advice spokesperson statement — as reproduced verbatim by NBC News SELF-STATED — the legacy-archive framing, “no email addresses or phone numbers,” experts engaged, system taken offline, identity protection offered.
nbcnews.com/tech/social-media/…-rcna221139
AFTERMATH & CONTEXT
NBC News — “10 women have sued the Tea app after user photos were hacked and leaked online” (Aug 2025) ATTRIBUTED — the lawsuits (filed = fact; allegations = unproven).
nbcnews.com/tech/social-media/…-rcna222880
NPR — “Tea encouraged its users to spill. Then the app’s data got leaked” (Aug 2, 2025) ATTRIBUTED — the whisper-network context and aftermath.
npr.org/2025/08/02/nx-s1-5483886/…
404 Media — “How Tea’s Founder Convinced Millions of Women to Spill Their Secrets, Then Exposed Them” (Aug 2025) ATTRIBUTED — founder Sean Cook and company profile; 404 Media questions parts of the founding backstory.
404media.co/how-teas-founder-convinced-millions…
Tea (app) — reference overview ATTRIBUTED — company name, founder, release, breach timeline; secondary aggregation, cross-checked to the primaries above.
en.wikipedia.org/wiki/Tea_(app)
The standard. Everything above is sourced to the original breach reporting (404 Media), major press (NBC News, TechCrunch, NPR, Engadget), a specialist security outlet (BleepingComputer), and the company’s own verbatim statement. The exposed bucket and the ID leak are stated as fact; the “doxxed its own users” characterization wears its framing; the lawsuits are labeled pending and their allegations unproven. The company is distinguished from its founder, no motive is asserted, and the defense — legacy system, no emails or phones taken, experts engaged, protection offered, attackers responsible for the spread — is presented at full strength. This archive never reproduces, links, or describes any individual’s leaked image or message; the focus is the company’s documented security failure, not its victims. The burden of proof is on us, not the subject. If it couldn’t survive a defamation challenge, it wouldn’t be on this page.