Platform · Online dating and matchmaking · General dating platform · Global
Online dating platform.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Zoosk, an online dating platform with tens of millions of users across multiple countries, suffered a data breach in January 2020 that exposed approximately 23.9 million user records. The breach was subsequently distributed widely across online hacking communities. The attack vector was a misconfiguration, meaning the exposure was not the result of sophisticated intrusion but of a security oversight within Zoosk's own systems. The breach was later provided to the public breach notification service Have I Been Pwned by the site breachbase.pw. The data exposed goes well beyond basic account information. Affected users had the following types of information compromised: names, nicknames, email addresses, dates of birth, geographic locations, physical attributes including height and weight, income levels, account balances, education levels, and family structure. Critically, the breach also included sexual orientations, religions, political views, ethnicities, relationship statuses, and habits around smoking and drinking. The combination of these fields is what makes this breach particularly dangerous. None of these categories were disclosed in isolation. An outside party holding this dataset can link a person's identity to their sexual orientation, faith, or ethnicity without that person ever having disclosed those details publicly. This creates real risk of targeted discrimination, blackmail, or harassment, regardless of how discreetly the individual used the platform. Zoosk notified users and prompted credential resets following the breach. No major regulatory enforcement action or class action settlement specific to this incident has been prominently documented. People affected should treat their email address as exposed and be alert to phishing attempts, romance scams using their profile details, or impersonation. Anyone whose sexual orientation, religion, or ethnicity appeared in this dataset should be aware that this information may be in circulation in criminal communities and could be used to target them specifically.
Full threat analysis, exploitation vectors, and principal guidance below.
10 additional sections · verified field analysis · defensive doctrine
23.9M records analyzed
Zoosk is an online dating platform operating across multiple countries, offering matching, messaging, and virtual gifting features to a predominantly adult user base. The company was founded in 2007 and has changed ownership multiple times, eventually being acquired by Spark Networks — the parent of Silversingles and other dating properties — in 2019. It operates as one of several platforms in the competitive general dating market.
Dating platforms collect user identity, profile details, photos, messages, relationship preferences, subscription records, and engagement activity tied to matchmaking workflows.
Zoosk has continued operating under Spark Networks, which has navigated a challenging environment for subscription dating platforms facing competition from app-based services. No major standalone Zoosk organizational changes have been prominently reported in the recent period.
In January 2020 Zoosk suffered a breach exposing approximately 24 million user records including email addresses, nicknames, dates of birth, genders, sexual orientations, relationship statuses, family structure, education, ethnicity, religion, financial profile data, physical attributes, and account balances. The breadth of personal profile data — particularly sexual orientation, religion, and ethnicity combined on a dating platform — is what places this record in the restricted tier. Zoosk notified users and initiated credential resets. No major settlement or regulatory action specific to this breach has been prominently documented.
• Financial fraud using exposed financial profile data | • Identity verification bypass using name + date of birth combination | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure
An intimate-data breach: preferences, orientation or explicit content linked to an identity create acute coercion and blackmail exposure. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.
We will only reveal whether a specific person appears in this breach to that person.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation