Drooid Logo
Back to story perspectives

Full Breakdown

Match Group Faces Data Breach Amidst Vishing Attack

1/29/2026, 2:00:57 AM

Overview of the Incident

On Wednesday, hackers known as Scattered LAPSUS$ Hunters announced they had stolen approximately 1.7GB of internal data from Match Group, the parent company of popular dating apps including Tinder, Hinge, and OkCupid. The breach reportedly includes users' unique advertising IDs, corporate receipts, and various internal documents. Match Group has confirmed it is investigating the incident and has engaged external cybersecurity experts to assist in the inquiry.

Details of the Breach

The hacking group claimed they gained access through a method known as vishing, which involves voice phishing to manipulate individuals into providing sensitive information. Specifically, they compromised the Okta Single Sign-On (SSO) dashboard of Match Group, which allowed them to connect to other applications such as Salesforce and AppsFlyer. A spokesperson for the hacking group stated, “we got in via vishing their Okta SSO.”

In response to the breach, a Match Group spokesperson emphasized that there is no evidence that user login credentials, financial information, or private communications were accessed. They noted that the incident affects a limited amount of user data and that notifications are being sent to impacted individuals.

Official Responses

AppsFlyer, a mobile marketing cloud platform mentioned in the breach, clarified that the incident did not originate from their systems and that their infrastructure remains secure. An AppsFlyer spokesperson stated, "Any implication that AppsFlyer was the source of the incident, or that data was exposed due to a compromise of AppsFlyer systems, is inaccurate."

Okta, the cybersecurity company involved, highlighted the importance of awareness regarding evolving social engineering techniques, including vishing. An Okta spokesperson remarked, "Okta Threat Intelligence routinely shares threat research to help companies protect against evolving social engineering techniques."

Criticism of Data Practices

In 2024, the Mozilla Foundation criticized Match Group's data collection and sharing practices across its major platforms, including Hinge and OkCupid. This criticism adds another layer of scrutiny to Match Group's handling of user data, particularly in light of the recent breach.

Conflicting Reports & Gaps

While Match Group asserts that the breach affects a limited amount of user data, the exact nature and extent of the compromised information remain unclear. The hacking group's claims about the data accessed have not been independently verified, leading to potential discrepancies in understanding the full impact of the incident.

Verbatim Quotes

  • “We are aware of claims being made online related to a recently identified security incident. Match Group takes the safety and security of our users seriously and acted quickly to terminate the unauthorized access. We continue to investigate with the assistance of external cybersecurity experts. There is no indication that user log-in credentials, financial information, or private communications were accessed. We believe the incident affects a limited amount of user data, and we are already in the process of notifying individuals, as appropriate.” — Match Group Spokesperson
  • “we got in via vishing their Okta SSO.” — Hacking Group Spokesperson

This incident underscores the vulnerabilities that can arise from social engineering attacks and the ongoing challenges companies face in safeguarding user data.