Zoosk 2020 Data Breach

Zoosk Dating Platform Breach (2020): 23 Million User Profiles Including Sexual Orientation, Religion & Political Views Exposed

Platform · Online dating and matchmaking · General dating platform · Global

Zoosk Dating Platform Breach (2020): 23 Million User Profiles Including Sexual Orientation, Religion & Political Views Exposed

Online dating platform.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly. Use the private exposure check at the bottom of this page.
Breach Risk Index i
44/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
23.9MRecords
2020Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
FinancialAccount Balance
IntimateSexual Orientation
Classification Tags
Cloud MisconfigurationDating & RelationshipsDatingUsers2020

Breach Summary

Zoosk, an online dating platform with tens of millions of users across multiple countries, suffered a data breach in January 2020 that exposed approximately 23.9 million user records. The breach was subsequently distributed widely across online hacking communities. The attack vector was a misconfiguration, meaning the exposure was not the result of sophisticated intrusion but of a security oversight within Zoosk's own systems. The breach was later provided to the public breach notification service Have I Been Pwned by the site breachbase.pw. The data exposed goes well beyond basic account information. Affected users had the following types of information compromised: names, nicknames, email addresses, dates of birth, geographic locations, physical attributes including height and weight, income levels, account balances, education levels, and family structure. Critically, the breach also included sexual orientations, religions, political views, ethnicities, relationship statuses, and habits around smoking and drinking. The combination of these fields is what makes this breach particularly dangerous. None of these categories were disclosed in isolation. An outside party holding this dataset can link a person's identity to their sexual orientation, faith, or ethnicity without that person ever having disclosed those details publicly. This creates real risk of targeted discrimination, blackmail, or harassment, regardless of how discreetly the individual used the platform. Zoosk notified users and prompted credential resets following the breach. No major regulatory enforcement action or class action settlement specific to this incident has been prominently documented. People affected should treat their email address as exposed and be alert to phishing attempts, romance scams using their profile details, or impersonation. Anyone whose sexual orientation, religion, or ethnicity appeared in this dataset should be aware that this information may be in circulation in criminal communities and could be used to target them specifically.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

23.9M records analyzed

About Zoosk

Zoosk is an online dating platform operating across multiple countries, offering matching, messaging, and virtual gifting features to a predominantly adult user base. The company was founded in 2007 and has changed ownership multiple times, eventually being acquired by Spark Networks — the parent of Silversingles and other dating properties — in 2019. It operates as one of several platforms in the competitive general dating market.

Why They Hold Your Data

Dating platforms collect user identity, profile details, photos, messages, relationship preferences, subscription records, and engagement activity tied to matchmaking workflows.

Recent Developments

Zoosk has continued operating under Spark Networks, which has navigated a challenging environment for subscription dating platforms facing competition from app-based services. No major standalone Zoosk organizational changes have been prominently reported in the recent period.

Data Points Exposed

17 verified field types
Account Balance High
Date of Birth High
Display Name
Education Information
Email Address
Ethnicity Or Race
Family Structure
Financial Profile
Full Name
Gender
Geographic location
Lifestyle Habits
Physical And Lifestyle Profile
Political Views
Relationship Status
Religion
Sexual Orientation High

Breach Impact

In January 2020 Zoosk suffered a breach exposing approximately 24 million user records including email addresses, nicknames, dates of birth, genders, sexual orientations, relationship statuses, family structure, education, ethnicity, religion, financial profile data, physical attributes, and account balances. The breadth of personal profile data — particularly sexual orientation, religion, and ethnicity combined on a dating platform — is what places this record in the restricted tier. Zoosk notified users and initiated credential resets. No major settlement or regulatory action specific to this breach has been prominently documented.

Exploitation & Downstream Threats

• Financial fraud using exposed financial profile data | • Identity verification bypass using name + date of birth combination | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure

Principal Risk Advisory

What this means for a principal

An intimate-data breach: preferences, orientation or explicit content linked to an identity create acute coercion and blackmail exposure. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Be alert to sextortion or blackmail attempts referencing this data and do not engage; preserve and report messages.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Protect Yourself: Limited Disclosure

Check If You’re Affected: Verification Required

Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.

We will only reveal whether a specific person appears in this breach to that person.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation