Plenty of Fish Reportedly Breached as 170 Million User Records Are Offered for Sale

A threat actor claims to be selling 170 million Plenty of Fish user records, with sample activity timestamps extending into August 2026.
Forum post advertising an alleged August 2026 Plenty of Fish database for sale, claiming 170 million user records containing account information. The listing includes a Plenty of Fish logo, pricing details, and a blurred sample of the purported database.
A threat actor claims to be selling an alleged August 2026 Plenty of Fish database containing approximately 170 million user records. The listing advertises user account information and includes a sample of the purported dataset, though the claims remain unverified.

A threat actor is offering what they claim is a newly obtained database containing approximately 170 million Plenty of Fish user records, with a sample showing highly sensitive dating profile information, account metadata, email addresses, location data, and bcrypt password hashes.

The seller claims the database dates from August 2026 and is being offered as a CSV file for $300. BreachNews reviewed the sample published with the listing and found records containing activity timestamps extending into August 2026, lending some support to the claim that the dataset is recent. However, the authenticity and claimed 170 million-record scale have not been independently verified.

Plenty of Fish had not issued any public statement regarding the alleged incident at time of publication.

Sample contains dating profiles and password hashes

The sample contains a broad range of information that would be particularly sensitive if tied to authentic Plenty of Fish accounts. Fields shown in the listing include:

  • User IDs and usernames
  • First names and email addresses
  • Dates of birth and ages
  • Gender and dating preferences
  • Country, state, city, and postal code
  • Profile headlines and relationship preferences
  • Marital and parental status
  • Body type, height, ethnicity, and religion
  • Smoking and drinking preferences
  • Education, occupation, and income ranges
  • Profile photo and engagement statistics
  • Verification and paid membership status
  • Last online timestamps
  • Signup platform and app version
  • Account status
  • Bcrypt password hashes

The password values visible in the sample follow a consistent bcrypt format using the $2a$08$ prefix. While bcrypt hashes are not plaintext passwords, exposure of password hashes can still create risk, particularly for users who reused passwords across other services.

Activity timestamps extend into August 2026

The seller specifically describes the database as a leak from August 2026. Several characteristics of the sample are consistent with that timeline.

Multiple records contain last_online_at values from July and August 2026, including accounts reportedly active as recently as August 6. Other records show 2026 account creation dates and paid membership activity, while application versions in the sample include releases identified as 5.65.0, 5.66.0, and 5.67.1.

The listed ages also generally correspond with the supplied dates of birth when calculated against 2026, suggesting the sample was at least constructed or updated using a current reference date rather than simply copied unchanged from an old database.

Those indicators make the seller’s recency claim plausible, but they do not establish that the records were actually obtained from Plenty of Fish in August.

Sample also raises authenticity questions

There are characteristics within the published records that prevent the sample from being treated as definitive proof of a new breach.

Many profile headlines follow highly repetitive patterns involving phrases about finding a connection, wanting a fresh start, enjoying coffee, hiking, road trips, restaurants, or live music. The sample also repeatedly cycles through a relatively small collection of occupations, religions, body types, education levels, and relationship preferences.

Some records contain unusual combinations of names, usernames, gender fields, demographic attributes, and email addresses. None of those characteristics individually demonstrate fabrication, and real dating platforms can contain unusual or inaccurate user-supplied information. Taken together, however, they leave open the possibility that the sample has been generated, enriched, modified, or assembled from multiple sources.

BreachNews therefore could not determine whether the sample represents an untouched production export from Plenty of Fish.

170 million record claim remains unverified

The seller claims the complete database contains approximately 170 million records, but the limited sample does not provide a way to validate that number.

If authentic, the combination of dating preferences, location information, profile characteristics, email addresses, account activity, and password hashes could create significant privacy and security risks. Dating platform data can be particularly sensitive because records may reveal intimate personal information that users would not expect to become publicly associated with their identity.

Plenty of Fish is part of Match Group’s portfolio of dating services. BreachNews will update this article if Plenty of Fish or Match Group confirms the incident, disputes the dataset, or additional evidence becomes available regarding the claimed August 2026 breach.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site