01Summary
On January 27, 2026, ShinyHunters claimed responsibility on their leak site for stealing over 10 million records. The data came primarily from the mobile marketing platform AppsFlyer and included advertising IDs, profile/usage data, subscription details, IP addresses, and internal corporate documents. Access was obtained via vishing (voice phishing) targeting Okta SSO credentials. Match Group confirmed investigating a security incident but stated that core user passwords, payment data, and private messages were not compromised.
02Background
Match Group operates some of the world's largest dating platforms, holding highly sensitive personal and relationship-related data for hundreds of millions of users worldwide.
03Key revelations
- 01Effectiveness of vishing attacks against enterprise SSO systems.
- 02Sensitivity of third-party marketing/analytics data in consumer apps.
- 03Risks associated with platforms like AppsFlyer.
04Technical analysis
Attackers used social engineering (vishing) to compromise employee Okta SSO credentials, then pivoted to internal dashboards and third-party marketing platforms like AppsFlyer.
- Attack vector
- Vishing / Social Engineering leading to SSO compromise
- Attack method
- Credential compromise, lateral movement, and data exfiltration
- Initial access
- Vishing (Voice Phishing)
- Lateral movement
- SSO / Okta credential abuse
- Exfiltration
- Bulk data extraction
Vulnerabilities exploited
- Human vulnerability to vishing
05Threat actor
ShinyHunters is a prolific cybercriminal extortion group known for vishing attacks, SSO compromise, and targeting large consumer/tech companies for financial gain.
Aliases
- SH
- Scattered LAPSUS$ Hunters
Attribution sources
- ShinyHunters leak site
- BleepingComputer
- The Register
- UpGuard
- Match Group statements
06Victims and impact
Countries affected
- Global
07Data exposed
Data types
- PII
- Mobile Advertising IDs (MAIDs)
- IP addresses
- Subscription transaction data
- User profile / usage data
- Internal corporate documents
08Financial damage
Reputational damage; potential class-action lawsuits; costs for user notifications and security enhancements.
09Timeline
- 2026-01-27ShinyHunters claims breach on leak site.
- 2026-01-29Match Group acknowledges investigating a security incident.
10Reaction and fallout
Public reaction
Significant concern among users regarding privacy, potential stalking, and blackmail risks.
11Legal
Ongoing investigations and class-action lawsuits filed.
Civil lawsuits
- Class-action lawsuits related to data privacy failures
12Aftermath
Security improvements
- Enhanced employee training against vishing
- Strengthened Okta/SSO monitoring and controls
13Significance and legacy
Significance
High-profile breach of major dating platforms demonstrating the rising threat of vishing and third-party data platform compromises.
Legacy
Increased awareness of social engineering risks in consumer tech companies handling sensitive personal data.
14Disclosure and media
- Authentication
- ShinyHunters leak site samples
Publishing organisations
- BleepingComputer
- The Register
- UpGuard
- Cybernews
15Field notes
- 01Data was primarily sourced from the third-party marketing platform AppsFlyer rather than core user databases.
16Resolution
Match Group contained the incident, notified affected users where required, and stated that core sensitive user data (passwords, messages, payment info) was not compromised.
17Sources
Official documents
- Match Group security incident statement
References
- [1]BleepingComputer reports
- [2]The Register coverage
- [3]UpGuard analysis
- [4]Match Group official statements









