Dating App Users' Data Leaked!

This is definitely a bad day for users of the Heyyo dating app. According to ZDNet, the creators of the dating app failed to password-protect the server containing the data of people using the application. As a result, the data of nearly 72,000 Heyyo users leaked – including personal data, photos, and their phone numbers!

The Heyyo mobile app, which helps people find their other half, has been installed by Play Store users more than 100,000 times. Due to the lack of password protection on the server containing information about daters, a staggering amount of data leaked. This included users' gender, phone numbers, email addresses, dates of birth, height, social media profiles (Facebook, Instagram), information about liked accounts, dating preferences, and details about their smartphones.

According to ZDNet, the creators of the Heyyo app, whose company is based in Istanbul, did not respond to the report about the problem. As a result, the server with sensitive data remained unprotected until yesterday (September 25), when the Turkish CERT took up the matter.

You Could Be a Commodity in the Hands of Cybercriminals

Data as a Commodity on the Black Market

It is currently unknown whether any third parties gained access to the data from the dating app's server. As noted by Kamil Sadkowski, senior threat analyst at ESET, data that leaks as a result of errors and security vulnerabilities can be a commodity for cybercriminals and end up on the "black market."
- This was the case with the high-profile leak of data from 617 million user accounts at Dubsmash and MyFitnessPal, among others. The stolen data was put up for sale on the Tor network for less than 20 bitcoins, or several hundred thousand zlotys – Sadkowski explains.

What Can Users Do When Their Data Is Leaked?

The expert from the antivirus company ESET advises immediately changing the password affected by the leak in all online services and applications where we used it, and being careful about what data we provide during registration. – If we don't have to provide our data, then let's not do it. This applies to home address, phone number, or sharing our location. The less of our data we provide online, the lower the likelihood of exposing ourselves – users – to unpleasant consequences of a leak – Sadkowski explains.

Summary

The Heyyo dating app left an unprotected server with data on nearly 72,000 users, including phone numbers, photos, and dating preferences. The creators from Istanbul did not respond to reports, and the Turkish CERT only took up the matter on September 25. ESET expert Kamil Sadkowski warns that such data ends up on the black market – a similar fate befell 617 million Dubsmash and MyFitnessPal accounts. He recommends immediately changing passwords and limiting the data provided during registration.