The iMeetings Breach: 9,169 Dating Site Profiles Exposed. Check Yours.
In November 2024, the database behind iMeetings, a Swedish online dating platform, was compromised and posted on underground forums. The breach exposed 9,169 user profiles, and the scope of the data goes well beyond a typical contact-info leak. Birthdays, genders, IP addresses, phone numbers, bcrypt-hashed passwords, and full names were all included. For a dating platform, this combination is particularly sensitive: it reveals not just who you are, but intimate details about your personal life and the fact that you use a dating service, information many people keep private.
Why This Is Dangerous
Dating site breaches occupy a uniquely damaging category. The data confirms membership on a platform that carries social and personal implications. For individuals who keep their dating life private, exposure on this platform could affect relationships, employment, or personal safety. Beyond the social dimension, the richness of the data, combining verified identity information with behavioral and biometric markers like birthday, gender, and location-linked IP addresses, makes it exceptionally useful for targeted fraud, extortion, and identity theft.
What Was Exposed
- Email Addresses - primary identifier for account linking and phishing attacks
- Phone Numbers - enable SMS phishing, SIM-swap fraud, and two-factor authentication bypass
- Bcrypt-Hashed Passwords - protected by strong hashing, but still vulnerable to offline cracking if passwords are weak or common
- Usernames - can identify individuals across multiple platforms
- First Names and Last Names - enable personalized social engineering
- IP Addresses - reveal approximate geographic location and internet service provider
- Birthdays - used to verify identity in account recovery and financial fraud
- Gender - adds to the profile detail available to threat actors
Why This Matters
The iMeetings breach creates direct risk across multiple threat vectors:
- Credential stuffing - Even with bcrypt hashing, weak or reused passwords can be cracked offline and tested against banking, email, and retail platforms.
- Account takeover - Phone numbers and emails together allow attackers to intercept two-factor authentication codes and seize accounts.
- Identity theft - Full name, birthday, phone number, and email together are enough to pass identity verification at many financial institutions.
- Extortion and fraud - Confirmed dating site membership combined with personal details creates leverage for sextortion-style threats and targeted scams.
How Dating Site Database Breaches Work
Dating platforms collect unusually rich personal profiles by design: they need enough detail to match users effectively. This makes their databases especially valuable targets. A database breach typically occurs when an attacker exploits a vulnerability in the web application layer, such as an SQL injection flaw, an unpatched CMS component, or a misconfigured cloud storage bucket with database backups. Once access is achieved, user tables can be extracted in a matter of minutes. Bcrypt hashing protects passwords from immediate use, but it does not prevent offline cracking attempts, and none of the other data types in this breach are protected by any form of encryption. After extraction, the data is typically posted on dark web forums or sold in private channels used by criminal actors.
Check If You Are Affected
The iMeetings breach: 9,169 user profiles. Yours might be one of them. Heroic's breach search engine indexes over 400 billion compromised records, including dating site databases and other sensitive platform leaks from around the world.
Search your email now at Heroic.com to find out whether your profile appeared in the iMeetings breach or any other known leak. If you find your data, change your password immediately and enable multi-factor authentication on every account that shares that email address.
Breach Breakdown
9,169 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds