Match Group A.I CyberSecurity Scoring
Match Group
Company Information
Website:https://www.mtch.com
Employees number:1,845
Number of followers:48,246
NAICS:5112
Industry Type:Software Development
Homepage:mtch.com
Match Group Risk Score (AI oriented)
Between 0 and 549
Match GroupSoftware Development
Updated:
28/04/2026
28/04/2026
366/1000
Critical
C
Match Group Global Score (TPRM)
xxxx
Match GroupSoftware Development
Score locked

Match GroupCritical
Current Score
366C (CRITICAL)
01000
7 incidents
-65.33 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
408
AUGUST 2026
405
JULY 2026
389
JUNE 2026
375
MAY 2026
370
APRIL 2026
423
Breach
27 Apr 2026 • Match Group
Rockstar Games, Anodot, McGraw Hill, Vimeo, Match Group and ADT: Video site Vimeo blames security incident on Anodot breach
Vimeo Data Breach via Third-Party Analytics Vendor Anodot
366
CRITICAL-57
ROCANOVIMMCGMATADT1777395770
Vimeo Confirms Data Breach via Third-Party Analytics Vendor Anodot
Vimeo has disclosed a data breach stemming from a security incident at Anodot, its third-party business analytics provider. The breach, attributed to the cybercriminal group ShinyHunters, exposed certain user and customer data, though no video content, login credentials, or payment information was compromised.
According to Vimeo’s statement, the accessed data primarily included technical metadata, video titles, and, in some cases, customer email addresses. The company responded by revoking Anodot’s access, removing the integration, and enlisting third-party security experts to investigate. Law enforcement has also been notified.
ShinyHunters listed Vimeo on its leak site on Tuesday, threatening to release stolen data unless a ransom was paid by Thursday. The group has been linked to a series of high-profile attacks in 2026, including breaches at McGraw Hill, ADT, and Rockstar Games with the latter also tied to the Anodot compromise. Reports suggest a broader supply-chain attack involving Anodot may have exposed data from multiple organizations.
Google Threat Intelligence previously detailed ShinyHunters’ tactics, which rely on phishing schemes rather than software vulnerabilities. Despite law enforcement crackdowns in 2025, the group remains active, recently targeting Match Group (owner of Tinder, Hinge, and OkCupid) before shifting focus to its current campaign. The investigation into the Vimeo breach is ongoing.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
495
Breach
31 Mar 2026 • Match Group
OkCupid and Match Group Americas: OkCupid, Match Group settle with FTC over unlawful data sharing with AI firm
OkCupid Settles with FTC Over Unauthorized Data Sharing with AI Firm
406
CRITICAL-89
MATOKC1775017551
OkCupid Settles with FTC Over Unauthorized Data Sharing with AI Firm
OkCupid and its parent company, Match Group Americas, have reached a settlement with the Federal Trade Commission (FTC) following allegations that the dating app improperly shared users' sensitive data with an AI solutions firm, Clarifai. According to the FTC, OkCupid granted Clarifai unrestricted access to nearly 3 million user photos, along with demographic and location data, without obtaining consent or offering an opt-out option. The agency linked the incident to OkCupid’s original founders, who had invested in Clarifai.
While OkCupid and Match have not admitted liability, the proposed settlement includes a 20-year legal order that would prohibit the companies from misrepresenting their data collection, storage, and sharing practices. If approved, the order would also mandate clearer disclosures about how sensitive user information including messages, health details, photos, videos, audio files, and location data is handled. The FTC’s restrictions would apply only to OkCupid and Match Group, excluding other Match-owned platforms like Hinge and Tinder.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
495
FEBRUARY 2026
567
Breach
21 Feb 2026 • Match Group
CarGurus and Match Group: CarGurus data breach exposes information of 12.4 million accounts
ShinyHunters Leaks 12.4 Million CarGurus Records in Massive Data Breach
483
CRITICAL-84
MATCAR1771957470
ShinyHunters Leaks 12.4 Million CarGurus Records in Massive Data Breach
The ShinyHunters extortion group has released over 12 million records allegedly stolen from CarGurus, a U.S.-based digital automotive marketplace serving millions across the U.S., Canada, and the U.K. The breach, disclosed on February 21, involved a 6.1GB archive containing sensitive user data, including:
- Email and IP addresses
- Full names and phone numbers
- Physical addresses
- User account IDs
- Finance pre-qualification and application details
- Dealer account information
- Subscription data
HaveIBeenPwned (HIBP) verified and added the dataset to its database, confirming that 3.7 million records were new, while the remaining 70% overlapped with prior breaches. Though CarGurus has not officially acknowledged the incident, the leaked data is now publicly accessible, raising concerns about phishing and fraud risks for affected users.
ShinyHunters, known for aggressive extortion tactics, has recently targeted multiple high-profile companies, including Odido, Optimizely, Figure, Canada Goose, Panera Bread, Match Group, and SoundCloud. The group typically gains access through social engineering, such as voice phishing, tricking employees into exposing credentials or installing malicious OAuth apps that grant API-level access to platforms like Salesforce, Okta, and Microsoft 365.
This breach underscores the growing threat of data extortion groups exploiting corporate systems to harvest and leak sensitive customer information.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
642
Breach
14 Feb 2026 • Match Group
Betterment, Match Group and Mercer Advisors: Canada Goose says ShinyHunters only breached old data
Canada Goose Historical Data Leak
564
CRITICAL-78
MATBETMER1771266248
Canada Goose Dismisses Recent Data Leak as Old Breach, No Signs of New Compromise
Canada Goose has confirmed that a recently advertised data leak involving over 600,000 customer records stems from a historical breach, with no evidence of a new system compromise. The luxury apparel company acknowledged the publication of an old dataset containing past customer transaction details but stated that its review found no unmasked financial data included.
The leaked records, posted by the cybercriminal group ShinyHunters on February 14, reportedly contain personally identifiable information (PII), partial payment details, and order data such as prices and delivery addresses. A preliminary analysis suggests the affected individuals are primarily based in North America and Europe.
ShinyHunters, which has launched its own data leak site in 2026, has been active in targeting high-profile organizations. Recent victims include Crunchbase, Betterment, SoundCloud, Match Group, Panera Bread, Harvard University, and Mercer Advisors. The group has previously exploited Okta accounts through voice phishing and was linked to attacks on Salesforce and its integrations, resulting in the theft of data from over 200 customers.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
699
Breach
28 Jan 2026 • Match Group
CrunchBase, Panera Bread, Match Group and Bumble: Bumble, Match, Panera Bread and CrunchBase hit by cyberattacks, Bloomberg News reports
Cyberattacks Target Bumble, Match, Panera Bread, and CrunchBase
641
MEDIUM-58
MATBUMCRUPAN1770710058
Cyberattacks Target Bumble, Match, Panera Bread, and CrunchBase
Several high-profile companies including dating platforms Bumble and Match, food chain Panera Bread, and corporate data provider CrunchBase were hit by cyberattacks, according to a Bloomberg News report on Wednesday. The incidents, confirmed by company spokespersons, varied in scope and impact.
Bumble stated that the intruders did not access its member database, accounts, direct messages, or profiles. Similarly, Match Group, parent company of Tinder, reported that a limited amount of user data was affected, though login credentials, financial information, and private communications remained secure.
CrunchBase disclosed that documents on its corporate network were compromised but contained the breach. Panera Bread confirmed an incident involving contact information and notified authorities.
The attacks highlight ongoing cybersecurity risks across industries, with companies emphasizing containment efforts and minimal exposure of sensitive data. No further details on the attackers or their motives were provided.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
725
Cyber Attack
22 Jan 2026 • Match Group
Okta, Hinge, Match Group, Match.com and OkCupid: Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match
Match Group Data Breach After ShinyHunters Leaks 10 Million User Records
699
CRITICAL-26
MATHINOKT1769712133
Match Group Confirms Data Breach After ShinyHunters Leaks 10 Million User Records
Match Group, the parent company behind popular dating platforms Tinder, Match.com, Meetic, OkCupid, and Hinge, has confirmed a cybersecurity incident involving the theft of user data. The breach was linked to the ShinyHunters threat group, which leaked 1.7 GB of compressed files containing approximately 10 million records from Hinge, Match, and OkCupid, along with internal documents.
In a statement to BleepingComputer, a Match Group spokesperson acknowledged the incident, stating the company acted swiftly to terminate unauthorized access. While the investigation is ongoing with external experts, Match Group reported no evidence that login credentials, financial information, or private user communications were compromised. Affected individuals are being notified as appropriate.
The attack stemmed from a social engineering campaign targeting single sign-on (SSO) accounts at Okta, Microsoft, and Google across over 100 organizations. In Match Group’s case, hackers gained access by compromising an Okta SSO account, which provided entry to AppsFlyer marketing analytics and cloud storage services like Google Drive and Dropbox. The phishing attempt used the domain matchinternal.com.
ShinyHunters claimed the stolen data included personally identifiable information (PII), though much of it consisted of tracking data. Security experts, including Mandiant’s CTO Charles Carmakal and Okta Threat Intelligence researcher Moussa Diallo, emphasized the need for phishing-resistant multi-factor authentication (MFA), such as FIDO2 security keys or passkeys, to mitigate such attacks. Okta also recommended strict app authorization policies and monitoring for anomalous API activity.
The incident highlights ongoing risks from social engineering, with some financial institutions testing live caller verification to combat fraudulent access attempts. Match Group, which serves over 80 million active users and generates $3.5 billion in annual revenue, remains a high-value target for cybercriminals.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
725
NOVEMBER 2025
724
OCTOBER 2025
723
SEPTEMBER 2025
776
Breach
01 Sep 2025 • Match Group
OkCupid, Match, CarMax and Edmunds.com: ShinyHunters ramp up new vishing campaign with 100s in crosshairs
ShinyHunters Expands Vishing Campaign Targeting High-Value Organizations with Advanced Phishing Kits
720
CRITICAL-56
CAREDMMAT1769740948
ShinyHunters Expands Vishing Campaign Targeting High-Value Organizations with Advanced Phishing Kits
Okta researchers have uncovered a surge in voice-based social engineering attacks linked to the notorious extortion group ShinyHunters (also tracked as UNC6040), which has targeted over 100 high-value organizations in the past month. The group’s latest campaign leverages real-time phishing kits and hybrid vishing techniques to bypass multi-factor authentication (MFA) and steal credentials, session tokens, and sensitive data.
### How the Attack Works
ShinyHunters employs "Live Phishing Panels" automated tools that enable man-in-the-middle (MitM) attacks on login sessions. Attackers impersonate IT support, guiding victims through fake MFA prompts while dynamically adjusting phishing pages to match legitimate authentication flows. For example:
- If a victim receives a push notification, the attacker instructs them to expect it, then manipulates the phishing site to display a fake confirmation.
- If the MFA method requires a one-time code, the attacker either provides the correct number (obtained in real time from the legitimate site) or modifies the phishing page to display it.
This approach defeats even push-based MFA, which was designed to counter automated phishing attacks.
### Recent Data Breaches Linked to ShinyHunters
The group has claimed responsibility for data leaks from multiple companies, including:
- Dating apps: Hinge, Match, OkCupid, and Bumble (though Match Group stated no financial or login data was compromised).
- Other victims: SoundCloud, CrunchBase, Betterment, CarMax, Edmunds.com, and Panera Bread.
While the exact breach methods remain unconfirmed, researchers note the attacks align with ShinyHunters’ known tactics, including:
- Credential theft via phishing kits.
- Session token hijacking for SSO platforms like Okta.
- Data exfiltration from SaaS applications.
### Broader Impact & Response
Okta’s advisory highlights a rise in similar attacks targeting Okta, Microsoft, and Google accounts, driven by commercial phishing kits optimized for voice-based social engineering. Cybersecurity firm Hudson Rock confirmed the leaked data matches ShinyHunters’ previous claims, reinforcing the group’s credibility.
Companies are advised to:
- Verify IT support calls through official channels.
- Audit OSS provider logs for suspicious device enrollments or new IP logins.
ShinyHunters, active since 2020, has a history of breaching major brands, often through employee account compromise. The latest campaign suggests an expansion of targets, with potential for further data leaks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Match Group ??
What was Match Group's A.I Rankiteo Cyber Score in August 2026 ??
What was Match Group's A.I Rankiteo Cyber Score in July 2026 ??
What was Match Group's A.I Rankiteo Cyber Score in June 2026 ??
What was Match Group's A.I Rankiteo Cyber Score in May 2026 ??
What was Match Group's A.I Rankiteo Cyber Score in April 2026 ??
What was Match Group's A.I Rankiteo Cyber Score in March 2026 ??
What was Match Group's A.I Rankiteo Cyber Score in February 2026 ??
What was Match Group's A.I Rankiteo Cyber Score in January 2026 ??
What was Match Group's A.I Rankiteo Cyber Score in December 2025 ??
What was Match Group's A.I Rankiteo Cyber Score in November 2025 ??
What was Match Group's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Match Group's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Match Group ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Match Group's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?