Back to News
Market Impact: 0.65

How we found TeaOnHer spilling users’ driver’s licenses in less than 10 minutes

AAPLGOOGGOOGLAMZN
Cybersecurity & Data PrivacyTechnology & InnovationRegulation & LegislationLegal & Litigation

The popular dating-gossip app TeaOnHer, despite its #2 ranking on the Apple App Store, was found to have critical security vulnerabilities, exposing thousands of users' sensitive personal data, including driver's licenses and government IDs, via an unauthenticated API and publicly accessible cloud storage. The developer, Xavier Lampkin, was initially unresponsive and dismissive of disclosure efforts, failing to commit to user or regulatory notification. While the flaws appear resolved post-disclosure, this incident highlights significant operational and privacy risks for companies handling sensitive user data, underscoring developer accountability and potential regulatory challenges in the broader digital economy.

Analysis

The dating-gossip app TeaOnHer, despite achieving the #2 rank in Apple's free app charts, exhibited gross negligence in its security architecture, leading to a significant data breach. Critical vulnerabilities, including an unauthenticated public-facing API and exposed administrative credentials, allowed unrestricted access to thousands of users' sensitive personal information, such as driver's licenses, government IDs, email addresses, and selfies stored in a publicly configured Amazon S3 bucket. The developer's response was equally alarming, characterized by initial denial, a lack of transparency, and no commitment to notifying affected users or regulators, which signals severe operational and governance deficiencies. This incident serves as a stark example of the inherent risks in the burgeoning app economy, particularly as new regulations may mandate the collection of such sensitive data for age verification. The ease with which these flaws were discovered—within 10 minutes—and the developer's dismissive attitude highlight a critical failure in both technical execution and corporate responsibility, posing potential reputational risk for the platforms (Apple's App Store, Amazon's AWS) that host such applications.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo