[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2i1isj4lscqfz":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":20,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"6a71c0f422171f910ebd825a","MatchGroup2026","Match Group Data Breach","match-group-2026","mtch.com","2026-01-01T00:00:00.000Z","2026-08-04T10:37:40.204Z","Match Group, Inc. 2025 Form 10-K filed with the U.S. Securities and Exchange Commission","https:\u002F\u002Fwww.sec.gov\u002FArchives\u002Fedgar\u002Fdata\u002F891103\u002F000089110326000025\u002Fmtch-20251231.htm",[14,16,17,18,19],"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmatch-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match\u002F","https:\u002F\u002Fwww.malwarebytes.com\u002Fblog\u002Fnews\u002F2026\u002F01\u002Fmatch-hinge-okcupid-and-panera-bread-breached-by-ransomware-group","https:\u002F\u002Fmtch.com\u002F","https:\u002F\u002Fcommons.wikimedia.org\u002Fwiki\u002FFile:Match_Group_Logo_2018.png",null,"unknown","people","Unknown",[25,26,27],"Email addresses","Personal information","Device usage tracking data","\u003Cp>\u003Cstrong>The Match Group data breach\u003C\u002Fstrong> was a January 2026 incident in which a threat group used social engineering to obtain limited unauthorized access to the company's corporate network and certain internal tools. Match Group confirmed in a regulatory filing that limited user data was affected.\u003C\u002Fp>\u003Cp>Public reporting connects the incident to usage and marketing-analytics data associated with Hinge, Match and OkCupid. The company said it found no indication that user login credentials, financial information or private communications were accessed.\u003C\u002Fp>\u003Ch2>How did the incident happen?\u003C\u002Fh2>\u003Cp>According to Match Group's filing with the U.S. Securities and Exchange Commission, the attackers used social engineering to enter the corporate network. Independent technical reporting says a corporate account provided access to an AppsFlyer marketing-analytics environment.\u003C\u002Fp>\u003Cp>The company said it terminated the unauthorized access and investigated with external experts. Match Group disputed the attacker's claim that Google Drive and Dropbox files were accessed.\u003C\u002Fp>\u003Ch2>What information was affected?\u003C\u002Fh2>\u003Cp>The confirmed scope includes limited user information and tracking or marketing-analytics data describing app usage. Source-scope evidence tied to the incident also supports the presence of email addresses.\u003C\u002Fp>\u003Cp>Match Group reported no evidence that login credentials, financial information or private communications were accessed. Those categories are therefore not included in this breach record.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The company did not disclose a total number of affected people. The threat actor's figure of 10 million refers to usage records, not a verified number of unique individuals.\u003C\u002Fp>\u003Cp>The affected-person count is therefore recorded as unknown. Repeated source records and email-formatted values were not converted into a people count.\u003C\u002Fp>\u003Ch2>What risks could the data create?\u003C\u002Fh2>\u003Cp>Email addresses combined with dating-app usage context may increase the risk of targeted phishing, account impersonation and unwanted personal association.\u003C\u002Fp>\u003Cp>Tracking data is not the same as private-message content, but it may still provide context about app activity and campaign interactions. The incident is therefore treated as sensitive.\u003C\u002Fp>\u003Ch2>What did Match Group do?\u003C\u002Fh2>\u003Cp>The company said it terminated the access, investigated with outside experts and began notifying individuals where appropriate. Its regulatory filing also says the incident did not have a material adverse effect on the company's business results.\u003C\u002Fp>\u003Ch2>What should users do?\u003C\u002Fh2>\u003Cp>People who receive an official notice from a Match Group application should check the affected data types stated in their own notice. Unexpected emails containing app-usage or campaign details should be verified before opening links.\u003C\u002Fp>\u003Cp>Although the company found no evidence that login credentials were accessed, users who reuse passwords should adopt unique passwords and enable multi-factor authentication.\u003C\u002Fp>","","Match Group Data Breach: Hinge User Data","Review Match Group's January 2026 breach, the confirmed Hinge and app-data scope, and practical steps users can take.","https:\u002F\u002Fupload.wikimedia.org\u002Fwikipedia\u002Fcommons\u002F6\u002F60\u002FMatch_Group_Logo_2018.png",false,{"name":35,"sector":36,"country":37,"website":10,"websiteArchiveUrl":29,"websiteStatus":38,"websiteCheckedAt":12},"Match Group","Technology","United States","active"]