LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Ladies.com Data Breach (2024)

MEDIUM severityConfirmedHow we verify

Ladies.com Data Breach (2024): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 3, 2024

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Ladies.com Data Breach (2024)

Reported July 3, 2024. Approximately 119K people affected.

MEDIUM
Severity
119K
People affected
16
Data types exposed
July 3, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Ladies.com Data Breach (2024) (reported July 3, 2024) exposed Bios, Dates of birth, Drinking habits and Education levels belonging to roughly 119K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
MEDIUM severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Ladies.com Data Breach (2024) breach?
119K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For people who used Ladies.com, a lesbian dating site, the 2024 data breach means personal details that were shared in confidence may now be outside the service’s control. With roughly 119,000 users affected, the exposure of identifying and intimate information creates lasting practical risks around privacy, safety, and unwanted contact.

Public reporting places the incident in 2024 and links it to an exposed Firebase database. The site operator later acknowledged the breach, after the website itself had already been shut down. Exact technical timelines and the full chain of events remain limited in public detail.

What happened

In 2024 the lesbian dating website Ladies.com suffered a data breach that affected 119,000 users. Reporting attributes the incident to an exposed Firebase database. The exposed material included extensive personal information such as email addresses, photos, sexual orientation, genders, dates of birth, and precise latitude and longitude, among other personal attributes.

The website was shut down in mid-2024. The site operator acknowledged the breach in December, together with a separate breach of the “Senior Dating” website run by the same organisation. The breach was reported on 3 July 2024. No further public detail has been released on the precise discovery date, the duration of exposure, or any forensic findings beyond the Firebase attribution.

How a breach like this happens

Incidents involving cloud databases such as Firebase commonly arise when access controls are left misconfigured. In typical cases a database is created for an application and is intended to be reachable only by authenticated clients or backend services. If authentication rules are set too permissively, or if the database is left publicly readable without requiring credentials, anyone who discovers the endpoint can download its contents.

Such exposures are often found by automated scanners that look for known cloud-service patterns, or by researchers and opportunistic actors who probe for open endpoints. Once the data is copied, it can be circulated on forums or sold. No specific threat group has been publicly attributed to the Ladies.com incident; the available information points only to the exposed database itself as the vector. Organisations that rely on third-party cloud services must continually audit rules and monitoring to reduce the chance of this class of failure.

About Ladies.com

Ladies.com operated as a dating platform aimed at lesbian users. Services of this kind typically collect profiles that include biographical text, photographs, demographic details, location data, and preferences that help match users. Because the platform’s purpose is romantic and social connection within a specific community, the data it holds is inherently sensitive: it can reveal sexual orientation, relationship status, physical appearance, and real-world whereabouts.

A breach at such a site is consequential precisely because the information is both identifying and intimate. Users often assume that details shared for matching will remain within the service’s controlled environment. When that boundary fails, the same data can be used for harassment, outing, or targeted fraud. The later acknowledgment by the operator, and the concurrent breach of a related senior-dating site under the same organisation, indicate that the incident formed part of a broader set of security failures rather than an isolated event.

What was likely exposed

Public reporting names the following categories as exposed: bios, dates of birth, drinking habits, education levels, email addresses, family structure, genders, and geographic locations. The same reporting also states that the breach included photos, sexual orientation, and precise latitude and longitude coordinates, among other personal attributes.

These elements together form detailed user profiles. Exact file formats, whether every record contained every field, and any additional data types that may have been present are not fully itemised in the available public summary. Organisations of this type routinely store the kinds of information listed above; the confirmed scale is 119,000 affected users. Readers should treat the listed categories as the known exposed set and regard any further specifics as unconfirmed.

What's at stake

For affected individuals the concrete risks include unwanted contact via email, attempts at social engineering that exploit knowledge of age, location or family structure, and the possibility of being identified or outed against their wishes. Precise geographic coordinates raise particular concerns about physical safety or stalking. Photos and bios can be reused for impersonation or non-consensual sharing.

For the organisation the stakes include loss of user trust, regulatory scrutiny under data-protection rules, and the operational cost of shutting down the service. Because the same operator also ran a senior-dating site that was likewise breached, the incident points to systemic control weaknesses rather than a one-off error. No public figures for financial loss or regulatory fines have been released.

Were you affected?

If you ever created an account on Ladies.com, treat the possibility of exposure as real. Change any password that may have been reused elsewhere, enable multi-factor authentication on important accounts, and monitor email for unexpected messages that reference personal details. Consider placing fraud alerts with credit bureaus if you are concerned about identity misuse. You can also run a free exposure scan of your email address to check whether it has appeared in known breach data sets. Stay alert for phishing that pretends to come from dating services or claims to offer “breach assistance.” Public detail remains limited; further official notices from the operator, if any, should be treated as the primary source of updates.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyLadies.com security record
74/100
DoxxScan™ · Moderate doxx risk
B 82Good record

1 reported incident on record.

See Ladies.com’s full breach history →

More recent breaches

Speedio Data Breach (2024)December 24, 2024Young Living Essential Oils Data Breach (2024)December 11, 2024Senior Dating Data Breach (2024)November 23, 2024FlipaClip Data Breach (2024)November 18, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Ladies.com Data Breach (2024) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram