Dating Sites Leak Means 34,759 Accounts Are Ready to Steal
HEROIC's threat intelligence operations detected a stealer log combolist labeled 34k Dating Sites being distributed on Telegram. Surfacing in February 2023, this sensitive dataset contains 34,759 records harvested from dating platform users, exposing email addresses, plaintext passwords, and the URLs of dating services where victims entered their login credentials.
Plaintext Dating Passwords Carry Unique Risks
All 34,759 passwords in this collection are stored in plaintext—completely unencrypted and instantly usable. Dating site credentials carry elevated risk because they connect directly to sensitive personal information: profile details, private messages, photos, and location data. Attackers with plaintext access to dating accounts do not just gain a login—they gain leverage for blackmail, social engineering, and targeted harassment campaigns.
What Was Exposed
- Email Addresses — personal accounts linked to dating profiles and relationship platforms
- Plaintext Passwords — unencrypted credentials providing direct access to dating accounts
- URLs — specific dating service login pages where each credential was captured
Dating Credentials Enable Extortion and Cross-Account Attacks
Beyond credential stuffing against other services, dating site credentials carry a distinct threat: sextortion and personal extortion. Attackers who access dating profiles can harvest private photos, intimate conversations, and personal details to coerce victims. Additionally, the 34,759 email-password pairs are tested against banking, email, and social media services through automated credential stuffing. If a victim reused their dating site password elsewhere, attackers gain a foothold into accounts with real financial and reputational consequences.
The Stealer Malware Behind Dating Data Theft
This combolist was compiled from infostealer malware infections that captured credentials indiscriminately from victims' browsers. Malware variants such as Stealc, Vidar, or RedLine extract all saved passwords regardless of the service—including dating platforms that users might prefer to keep private. Threat actors then filter and categorize the stolen logs by industry, creating targeted collections like this dating-focused dump. These niche compilations are valued in underground markets specifically because of their potential for extortion schemes.
Check If Your Credentials Were Exposed
HEROIC's breach intelligence database indexes over 400 billion records from data breaches, stealer logs, and dark web sources worldwide. Use HEROIC's free breach scanner to check if your email or credentials appear in the 34k Dating Sites combolist or any other known breach. If you find a match, immediately change your dating site passwords as well as any other accounts using the same credentials, and enable two-factor authentication to prevent unauthorized access.
Breach Breakdown
34,759 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds