Researchers from Cybernews discovered that around 1.5 million images were exposed from a leak targeting LGBTQ and kink dating apps on iOS devices.
The apps were all developed by M.A.D. Mobile Apps Developers Limited, and included BDSM People, CHICA, TRANSLOVE, PINK, and BRISH, exposing sensitive user data.
Hackers exploited publicly accessible hardcoded ‘secrets’ in the apps code, which allowed unauthorised access to storage buckets containing highly sensitive content.
These secrets include API keys, passwords or encryption keys – exposing these can be dangerous as credentials placed in client application are accessible to anyone, and are easily abused by threat actors.
This puts users at risk of extortion, social engineering attacks, and even persecution in regions where LGBTQ+ identities are criminalised.
The most disastrous of these the Cybernews researchers found were the leaked secrets which granted access to user photos in Google Cloud Storage buckets, which had no passwords.
The apps – which were aimed at the BDSM, sugar, and LGBTQ+ communities – services around 800,000 to 900,000 people.
M.A.D. Mobile was initially informed about the leak on 20 January, but according to the BBC, did not take action until the news outlet notified them last week.
The firm has since fixed the problem, but has yet to explain why it happened or how it failed to protect the sensitive data.
1.5 million private photos were exposed, including profile pictures and pictures sent via direct messaging. Text and user names were not stored in the same way as these photos, so it would be difficult for threat actors to link photos and names of users, but the risk exists.
Recommended reading
- Almost 20 Million UK User Accounts Leaked This Year
- Northern Ireland Police Service Fined £750K After Data Breach
- Which Data Breaches Had Everyone Talking This Year?
Typically, cyber research teams wait until a breach has been secured before publishing their findings. However, as Cybernews had already informed M.A.D. Mobile of the breach back in January and still received no response, the research team decided to raise the alarm bells and at least inform users of the leak.
The research team’s findings were part of a larger survey of iOS App vulnerabilities. The research team downloaded 156,000 iOS apps, finding that 71% of all analysed had at least one secret exposed. On average, apps exposed 5.2 secrets in their code.





