By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: 1,500,000 private photos sent on gay, fetish and sugar daddy dating apps leaked
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > 1,500,000 private photos sent on gay, fetish and sugar daddy dating apps leaked
News

1,500,000 private photos sent on gay, fetish and sugar daddy dating apps leaked

News Room
Last updated: 2025/03/28 at 12:13 PM
News Room Published 28 March 2025
Share
SHARE
The photographs include profile pictures and those sent privately between users (Picture: Getty/Metro)

More than 1,500,000 photographs shared on LGBTQ+, fetish and sugar daddy dating apps have been ‘leaked’, researchers say.

Sensitive information, including passwords, was published in the code of five mobile dating apps.

This information, called ‘secrets’, can be used by hackers to crack open the Google Cloud Storage bucket where an app user’s photos are stored.

Researchers from the independent news outlet Cybernews found that this bucket was not password protected.

This meant the images inside, which included profile pictures, public posts, privately sent photos and even images used to verify a user’s identity, were publicly accessible to those who knew where to look.

The affected iOS apps – BDSM People, CHICA, TRANSLOVE, PINK, and BRISH – are all owned by MAD Mobile Apps Developers Limited, a London-based software company.

The lead researcher, Aras Nazarovas, told Metro that the team are not aware of any third parties accessing this information.

Close-up of a man using an online dating app on his mobile phone. Cropped shot of a man hand holding a cell phone using an online dating application.
Many of the exposed apps were used by the LGBTQ+ community (Picture: Getty Images)

MAD has not yet commented.

Join Metro’s LGBTQ+ community on WhatsApp

With thousands of members from all over the world, our vibrant LGBTQ+ WhatsApp channel is a hub for all the latest news and important issues that face the LGBTQ+ community.

Simply click on this link, select ‘Join Chat’ and you’re in! Don’t forget to turn on notifications!

Why user photos were exposed is a simple one. MAD uses the same architecture for the five apps, Nazarovas, a junior information security researcher at Cybernews, told Metro.

‘The affected dating apps were developed in an insecure manner, storing all user-uploaded images in a public Google Cloud Storage bucket,’ he said.

‘This issue was left unnoticed until the Cybernews research team found these publicly accessible cloud storage buckets after scanning 156,000 iOS apps for sensitive information.’

Nazarovas said that the leaky storage bucket doesn’t mean scammers could access a person’s username, email or messages.

But they could track down a user’s identity by using OSINT, or open-source intelligence techniques, such as reverse image searching. Something especially troubling for LGBTQ+ users who may not be open about their identity.

1,500,000 private photos exposed from LGBTQ+, BDSM and sugar dating apps
The bucket for BRISH, a queer dating app, contained some 404,000 photos (Picture: Apple)

‘Images accessed by bad actors could have been used for blackmail and intimidation,’ Nazarovas warned.

‘Finding out that these images were leaked would likely cause distress, trust issues, as well as other harm to the user’s mental health. Especially when approached with a blackmail demand.’

App developers, the team found, stored user secrets as ‘plaintext credentials’, a way of storing private info akin to writing down a password on a sticky note.

Among the apps was BDSM People, ‘a private app for those looking for something more than just a date’, its App Store description says.

The app is for people interested in bondage, discipline, dominance, submission and sadomasochism, or BDSM.

Yet the secrets tucked away in its application code allowed access to 1,600,000 files and 128GB of data, including 541,000 images.

1,500,000 private photos exposed from LGBTQ+, BDSM and sugar dating apps
BDSM People lets users connect with ‘like-minded people around the world’ (Picture: Apple)

CHICA, meanwhile, is an app for ‘sugar-dating’. This involves a ‘sugar baby’ connecting with a ‘sugar daddy’ in a relationship that offers financial support in exchange for companionship and possibly sex.

Researchers said CHICA’s code contained ways for people to access almost 45GB of data, including 133,000 images of app users.

Three apps tailored to LGBTQ+ people, TRANSLOVE, PINK and BRISH, were also vulnerable. Each of their buckets contained 142,000, 620,000 and 404,000 leaks, respectively.

PINK, a lesbian dating app, says its team verifies profiles and moderates the app to keep it ‘secure’.

But according to Cybernews, 45,000 blurred pictures, 43,000 pictures sent through chat, 1,000 pictures posted on comment sections, 12,000 images removed by moderators, 112,000 photos included in posts, 363,000 profile pictures and 44,000 photos used to verify profiles were all exposed.

‘The results of this investigation show that some apps can be incredibly insecure, exposing private user data to the open internet and leaving it completely unprotected,’ said Nazarovas.

1,500,000 private photos exposed from LGBTQ+, BDSM and sugar dating apps
Another app left exposed, CHICA, has been downloaded from the Apple App Store more than 80,000 times (Picture: Apple)

‘While some other apps employ better cybersecurity practices, these apps are also not without dangers, as private information could be shared without permission by the person you’re chatting with.’

Nazarovas said that app developers and distributors alike need to do more to protect user data.

App stores, he suggested, could scan submitted apps for basic security issues and loopholes.

‘While it may not catch 100% of such vulnerabilities, it would significantly reduce such cases,’ Nazarovas added.

Get in touch with our news team by emailing us at [email protected].

For more stories like this, check our news page.

Arrow MORE: ‘We’re young women with herpes — and we won’t be shamed’

Arrow MORE: Gay people are still facing ‘exorcisms’ to ‘cure them’ of their sexuality

Arrow MORE: Our families don’t approve of our relationship — secret phone sex keeps it alive

News Updates

Stay on top of the headlines with daily email updates.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article GNOME 48 & KDE Plasma 6.3 Delivering Great Wayland Desktop Experience On Ubuntu 25.04 For Linux Gaming Review
Next Article Meet HackerNoon Top Writer: the frog society – Discussing Tech and The Highs and Lows of Writing | HackerNoon
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Starlink Cellular’s T-Mobile service to grow with third-party app data
News
Baichuan AI launches enhanced financial model, surpassing GPT-4o accuracy · TechNode
Computing
Make internet a safer place for the whole family with AdGuard, now A$24 for life
News
👨🏿‍🚀 Daily – Starlink is live (again) in Kenya |
Computing

You Might also Like

News

Starlink Cellular’s T-Mobile service to grow with third-party app data

3 Min Read
News

Make internet a safer place for the whole family with AdGuard, now A$24 for life

2 Min Read
News

Study claims a passing star could fling Earth out of the solar system

3 Min Read
News

Apple Wallet App on iPhone Now Lets You Add Japan’s My Number Card

7 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?