Skip to content
NetarxImpact Database
Credential Phishing PortalUnknownReported

Match Group SSO phished via lookalike domain; ShinyHunters claims 10 million dating records

Match Group (Match, Hinge, OkCupid) · Technology · United States · January 29, 2026

People or records affected
10,000,000
10.0M as reported

What happened

ShinyHunters compromised a Match Group employee's Okta single sign-on account through a phishing site hosted at the lookalike domain matchinternal.com, then pivoted into the company's AppsFlyer marketing analytics tenant and associated cloud storage. The group leaked 1.7 GB of compressed files it said contained about 10 million records covering Hinge, Match and OkCupid users along with internal documents. Match Group confirmed the incident on 29 January 2026, said it terminated the unauthorized access quickly, and stated that login credentials, financial data and private communications were not accessed, characterising most of the data as tracking information. Records affected is the attacker's claim, not a company figure.

How the deception worked

The attackers registered matchinternal.com, a domain that reads as a legitimate Match Group internal property, and stood up a credential-capture page mimicking the company's Okta sign-in. An employee was steered to that page and entered corporate SSO credentials, which the attackers relayed to the real Okta tenant in real time to defeat multi-factor authentication. The trust signal abused was the company-branded domain plus the familiar Okta login screen. With that session the group reached a downstream marketing analytics platform, AppsFlyer, and cloud storage, exfiltrating user tracking records and internal documents before Match Group revoked the access.

The control that would have caught it· our reading, not a claim from the sources

Origin-bound phishing-resistant authentication such as FIDO2 passkeys would have refused to sign in to a lookalike domain, and continuous monitoring of newly registered domains containing the brand name would have flagged matchinternal.com before it was used.

Sources (2)

  1. Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match
    BleepingComputer·bleepingcomputer.comOpen ↗
  2. ShinyHunters claims Okta customer breaches, leaks data belonging to 3 orgs
    The Register·theregister.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.