LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › WhiteDate Data Breach (2025)

HIGH severityConfirmedHow we verify

WhiteDate Data Breach (2025): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·December 29, 2025

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

WhiteDate Data Breach (2025)

Reported December 29, 2025. Approximately 20K people affected.

HIGH
Severity
20K
People affected
22
Data types exposed
December 29, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

WhiteDate disclosed a data breach affecting 20,000 users on December 29, 2025. Individuals should check if their information was exposed and take appropriate protective steps.

Severity & verification
HIGH severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the WhiteDate Data Breach (2025) breach?
20K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In December 2025, the dating platform WhiteDate suffered a data breach that exposed information belonging to 20,000 people. The material was subsequently posted online and later supplied to the Have I Been Pwned database, where it became publicly searchable. The exposure is significant because the records contain details that users typically share only within a dating context, including private messages and identifiers that can link online activity to real-world identities.

Breaking down the breach

Public reporting on the incident began on 29 December 2025. An initial portion of the data, containing 6.1k unique email addresses, appeared first. A fuller set was later added to Have I Been Pwned, bringing the total to 20k unique email addresses. The records include usernames, IP addresses, private messages and phpBB password hashes. No information has been released about the method of intrusion, the timeline of access, or whether the organisation detected the event before the data surfaced publicly.

How a breach like this happens

Incidents involving dating platforms often begin with the compromise of a web application or its supporting infrastructure. Attackers may obtain entry through unpatched software, weak authentication controls or stolen credentials. Once inside, they can extract database tables that store user profiles, messages and authentication data. The material is then packaged and distributed on leak sites or sold. In many cases the precise entry point remains undisclosed because the affected organisation does not publish a technical report.

Who is WhiteDate?

WhiteDate operates as an online dating service that describes itself as intended “for a Europid vision.” Like other niche dating sites, it collects detailed personal information to facilitate matches. Such platforms routinely store profile text, demographic attributes, contact details and communication logs. A breach at any dating service is consequential because the data are inherently intimate and often include information users do not publish elsewhere.

The information in question

The breach record lists ages, astrological signs, bios, device information, education levels, email addresses, family structure and forum posts. Additional fields reported in the leaked material include references to physical appearance, income, IQ, usernames, IP addresses, private messages and phpBB password hashes. The exact scope of every field present in the full dataset has not been independently verified beyond these descriptions.

The real-world impact

Individuals whose records appear in the dataset may receive unsolicited contact based on the exposed email addresses and profile details. Password hashes, if cracked, could allow access to the WhiteDate account or to other services where the same credentials were reused. IP addresses and device information can assist in correlating online activity with physical locations. The organisation faces reputational damage and potential regulatory scrutiny over the protection of user data.

If your data was in this breach

Change the password on your WhiteDate account and on any other service where the same password was used. Enable multi-factor authentication wherever available. Review privacy settings on other platforms to limit the visibility of similar personal details. You can run a free exposure scan of your email address against known breach data to determine whether your information appears in this or other incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyWhiteDate security record
68/100
DoxxScan™ · Moderate doxx risk
C 66Mixed record

1 reported incident on record.

See WhiteDate’s full breach history →

More recent breaches

Raaga Data Breach (2025)December 15, 2025Dragonica Lunaris Data Breach (2025)December 6, 2025Operation Endgame 3.0 Data Breach (2025)November 13, 2025Zilvia.net Data Breach (2025)November 6, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the WhiteDate Data Breach (2025) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram