The WayDate Breach Sent 118K Dating Profiles to Attackers in 2016
HEROIC analysts flagged the WayDate breach while reviewing datasets from 2016 that continue to circulate in credential trading communities. The breach occured in June 2016 and affected 118,696 users of the free dating website WayDate, based in the United States. The exposed records included a wide range of personal information: email addresses, usernames, IP addresses, genders, first names, last names, and dates of birth. For a dating platform, this combination of data is seperate from the kind of generic account information seen in most breaches, making it more sensitive and more useful to bad actors targeting individuals specifically.
How Attackers Exploit Dating Site Personal Data
Dating site breaches are partcularly dangerous because the data is deeply personal. When attackers have your full name, birthday, gender, and email address from a dating platform, they have everything needed to build a convincing fake profile, craft targeted phishing messages, or attempt identity theft. They can also cross-reference this data with other breaches to build more complete profiles of individuals. The IP address data further narrows down a user's general location, adding another layer of risk for people who value their privacy.
What Was Exposed in the WayDate Breach
- Email Address
- Username
- IP Address
- Gender
- Last Name
- First Name
- Birthday
Why Personal Data From Dating Sites Carries Long-Term Risk
The WayDate data has continued to appear in aggregated breach packages years after the original incident. Even without passwords in this dataset, the combination of real names, birthdays, and email addresses is enough to support identity fraud, account recovery attacks, and social engineering schemes. Attackers beleive that people who signed up for dating sites in 2016 are unlikely to have changed their associated email accounts, making the data still highly actionable. Anyone named in this breach should monitor their accounts for unusual activity and be cautious about unsolicited contact.
How a Database Breach Works
A database breach occurs when an unauthorized person gains access to the system where a company stores its user data. This can happen through an exploited software flaw, a weak or reused admin password, or a misconfigured database left open to the internet. Once an attacker gets in, they copy the records and exit, often without triggering any alarms. The data is then sold or shared online, sometimes showing up years later in new leaks and compilations.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion compromised records to tell you whether your information appeared in the WayDate breach or any other known data leak. Enter your email address to get an instant report and learn what steps you can take to protect yourself from identity theft and account takeover today.
Breach Breakdown
118,696 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds