Dating-app giant Match Group acknowledged a cybersecurity incident on January 28-29, 2026, after the extortion crew ShinyHunters claimed it had stolen more than 10 million records from the company's platforms, including Match.com, Hinge, and OkCupid. Match Group's public statement characterized the exposed data as a limited amount of user data plus some internal files, while reporting by The Register and others noted the claim surfaced on a dark-web leak site on January 28. The scope of the theft — what was actually taken versus what was claimed — remained unverified as of early February.
What happened?
ShinyHunters, a crew known for data extortion against high-profile targets, posted a claim of access to over 10 million Match Group-related records. The company responded that it had identified a cybersecurity incident and that a limited amount of user data and internal files was exposed; coverage by The Register on January 29 and analyses by UpGuard and Malwarebytes described the claim and the company's response in detail. Some reporting pointed to a third-party analytics connection as a possible vector, though nothing was confirmed publicly in the days after disclosure. Claims in extortion cases routinely exceed what forensics later substantiates — both directions stay open until Match Group or regulators publish findings.
Who is affected?
Users of Match.com, Hinge, and OkCupid during the relevant period — which the company had not precisely delimited in its initial statements. The categories of data in extortion claims of this shape typically include profile information, contact details, and activity metadata; payment-card data is a separate, more heavily regulated category, and no confirmed statement addressed it in the initial disclosure. Anyone with an account on those platforms should act on the assumption that profile-linked contact details were exposed, which is the basis for the steps below.
What should affected users do now?
- Change the password on the affected app, and anywhere else it was reused — credential reuse is how a dating-app spill becomes an email takeover.
- Expect targeted phishing. Data of this kind fuels convincing romance-themed and account-suspension lures. Treat any email or text about your dating accounts as suspicious and navigate to the app directly.
- Turn on two-factor authentication for the apps that offer it and for the email address tied to them.
- Watch for account-suspension scams — messages claiming your account will be deleted unless you verify payment details are the standard follow-up fraud to breaches of consumer platforms.
- Report suspicious messages to the FTC at reportfraud.ftc.gov and, for U.S. users, file with the FBI's IC3 if you suffer losses.
This incident is the second major consumer-platform extortion episode pinned to ShinyHunters in recent memory, and the crew's pattern — breach, leak-site claim, deadline, escalation — argues for treating any connected account as exposed until the company's investigation concludes.
For more context, read Why schools are ransomware's favorite target.
For more context, read cyber insurance.
For more context, read cybersecurity skills shortage.

