Online Daters Targeted in the 106K Record Free Date USA Breach
HEROIC analysts identified the Free Date USA database while monitoring Telegram channels where dating site breaches are increasingly being aggregated and traded together. The breach occured in November 2016, exposing 106,472 records from a US-based online dating platform. What made this dataset stand out was the presence of plaintext passwords, meaning any attacker who recieved a copy of this dump could immediately use the credentials without any cracking tools or technical effort. Dating site breaches carry a particularly high personal risk because of the sensitive nature of the profiles involved.
Why Plaintext Passwords From a Dating Site Are Especially Dangerous
Dating platforms hold personal information that users often keep seperate from their professional or public identity. When plaintext passwords from a site like Free Date USA are leaked, attackers can use them directly to attempt logins on email accounts, social media, banking apps, and other platforms where the same password was reused. This is partcularly concerning because users who registered on dating sites often use passwords they consider private, not realizing those same credentials unlock far more sensitive accounts.
What Was Exposed in the Free Date USA Breach
- User account records (106,472 total)
- Plaintext passwords
- Dating profile data from US users
- Email addresses linked to personal accounts
How Dating Site Breaches Enable Romance Scams and Account Takeover
Data from dating sites is valuable for more than credential stuffing. Attackers use profile information to craft convincing romance scam personas, impersonate real users, and target victims with personalized phishing messages. When combined with plaintext passwords, as in this case, the risk escalates to full account takeover across any platform where the email and password combination was reused. Identity theft and financial fraud become straightforward when an attacker holds both the login credentials and enough personal context to impersonate someone convincingly.
How Database Breaches Work
A database breach happens when an attacker gains unauthorized access to a platform's stored user data, often by exploiting a vulnerability in the site's software or by using stolen administrative credentials. Once inside, the attacker copies the database and distributes it through private channels. Dating site databases are a common target because they tend to hold personal and sensitive profile data alongside login credentials, making them highly valuable in underground markets.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records, including the Free Date USA dataset and hundreds of other dating site breaches. Find out instantly whether your email or credentials are circulating on the dark web. Run your free check at HEROIC.com today.
Breach Breakdown
106,472 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds