A massive data breach involving a dating service known as "419 Dating - Chat & Flirt," developed by a Hong Kong-based company Siling App, has exposed sensitive information from over 260,000 dating app accounts, along with 340 gigabytes of images and private chat logs.
The breach occurred within an Amazon Web Services S3 storage bucket, leaving the data easily accessible to the public. The exposed data contained personal details, such as names, email addresses, and geolocation data of predominantly United States and Canadian customers. Private user messages, chat logs, audio files, profile images, and shared pictures between users were also compromised.
Independent researcher Jeremiah Fowler, co-founder of Security Discovery, made this alarming discovery in April 2023. According to the security researcher, the vast 340 gigabytes of data comprised a staggering 2,357,896 files and 600 compressed server logs. One of these server logs revealed over 260,000 user account email addresses tied to major email providers, including Gmail, Yahoo Mail, and iCloud Mail.
The exposed data remained accessible via the public internet until it was brought to the attention of Siling App. After being notified by Fowler, the app developer promptly secured the misconfigured server. However, it remains uncertain how long the data had been exposed or if any third party had gained unauthorized access to the sensitive information, including highly private images and chat histories.
Fowler emphasized the grave risks of the breach, noting that the data allowed for easy cross-referencing of usernames, email addresses, images, chat logs, messages, and geographic locations. As a result, users’ true identities and addresses, even if they used pseudonyms, could be established without much difficulty. The vast amount of adult content exposed poses serious concerns, potentially making users susceptible to extortion attacks, social engineering scams, and other harmful privacy violations.
Following the discovery by Fowler, the dating app was swiftly removed from both the Google Play marketplace and Apple’s App Store. Despite the headquarters in Hong Kong, the company did not respond to Fowler’s notification regarding the data breach, leading to the app’s sudden disappearance from major app stores. Currently, there is no indication that malicious actors have gained access to the exposed data.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543