Class-action lawsuit filed after data breach on women-focused dating safety platform
A class-action lawsuit has been filed against Tea, an app designed to promote dating safety by allowing women to post anonymous reviews of men. The legal action, initiated by a Northern California woman known as Jane Doe, alleges negligence, invasion of privacy, and violations of federal law following a data leak compromising over 72,000 sensitive images as a result of a misconfigured database.
The data exposed in the breach included personal selfies of users as well as pictures of official identification documents such as driver’s licenses and passports used by Tea for identity verification purposes. The images found their way onto 4chan, an infamous online platform known for perpetuating harassment against women, after users discovered the vulnerable database.
Describing the incident as a blatant security lapse, the lawsuit likens the situation to leaving the bank vault unlocked with a sign inviting theft. Seeking redress and legal remedies, the plaintiffs emphasized the need for a comprehensive response to address the compromised personal information and prevent future breaches through enhanced security protocols.
Following the exposure of the data cache on 4chan, the files were downloaded in large quantities by users, propagating links for widespread access via X. Despite being notified, both X and 4chan allegedly failed to promptly remove the shared data, contributing to its dissemination to a broader audience beyond the original forum. The lawsuit contends that the irresponsive actions of X Corp. exacerbated the data breach, contrary to good faith behavior.
A troubling discovery compounded the Tea app’s woes when a security researcher revealed unauthorized access to more than one million private messages stored on the platform, divulging intimate discussions on sensitive topics including abortion and infidelity. Tea promptly deactivated its direct messaging function in response to the breach and acknowledged the compromise of private communications as part of the original incident.
The legal complaint underscores the ironical betrayal of trust faced by users relying on Tea to safeguard their identities and ensure safety in dating interactions. The plaintiff, who sought anonymity to protect herself while reporting misconduct, now grapples with fears of identity theft, biometric data misuse, and potential retribution from the subject of her alert on the app. Tea’s swift action in the wake of the security lapses, disabling implicated systems as a precaution, signals an acknowledgment of the severity of the data breach and a commitment to address the vulnerabilities that were exploited.
The unfolding events surrounding Tea’s data exposure and subsequent legal action underscore the imperative for robust data protection mechanisms in the realm of online platforms, particularly those catering to personal safety and security. As the class-action lawsuit unfolds, the outcome is awaited with anticipation for the accountability and corrective measures expected from the implicated parties involved in the breach.