110 million Bumble users for $300? Hackers’ claim raises eyebrows
More people affected than are registered on Bumble?

Illustration by Cybernews
- Hackers claim they are selling data on 110 million Bumble users for $300, but researchers question the figure.
- Cybernews researchers say the 36 sample records look legitimate and include contact details and dating profile information.
- Exposed profiles could help criminals personalize scams, impersonate users, or harass vulnerable people.
- Bumble has not responded yet, and researchers cannot confirm whether the new claim links to an earlier listing.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Hackers claim 110 million Bumble users are exposed as dating profiles appear for sale.
A database allegedly containing information on 110 million Bumble users is being offered for just $300 on an underground hacker forum.
The claims are raising questions over whether a massive dating app breach has occurred, whether the data was gathered through other means, or whether the alleged attackers are simply lying.
Bumble has more than 40 million active users, meaning that if the 110 million figure were legit, the alleged dataset would extend far beyond Bumble's current active user base.
The alleged dataset reportedly contains phone numbers, email addresses, demographic information, and dating profile details. The seller provided 36 sample records, which Cybernews researchers have examined.
110 million users for $300: Too good to be true?
Thirty-six data samples included personal user data and dating profile information. However, the sheer size of the alleged database is the first red flag. According to our researchers, if the dataset really contains data on 110 million individuals, the price tag would be significantly higher.
Also, the numbers do not add up, as there are more “affected” users than there are Bumble users. However, Cybernews researchers say that the data visible in the samples appears legitimate rather than fake.
Our researchers also noted that some timestamps appear remarkably recent, including records dated around August 2026. That suggests the samples may not be an old Bumble database recycled from an earlier incident.
If exposed, a dating profile can reveal how someone describes themselves, their interests, location or demographic characteristics, and other details they have chosen to share while looking for a relationship.
With that information, criminals could potentially construct highly personalized phishing attacks.
The information could also be used to impersonate someone on another dating platform, particularly if the person's profile description, personal details, and contact information are all available in the same dataset, potentially leading to pig butchering scams.
“The impact would be personalized scams mainly. There is a risk for impersonation in other dating platforms, since the whole profile description is on a silver platter,” our researchers said.
Cybernews researchers also warned of a risk of harassment. This could be particularly serious for LGBTQ+ users, for whom the exposure of information connected to dating may pose physical risks in some societies.
Cybernews has reached out to Bumble for comment. We will update this article once we receive a response.
Alleged Bumble data has previously surfaced on hacker forums
In June, another alleged Bumble dataset surfaced on underground forums. Attackers posted the Bumble data leak announcement on a popular data leak forum, claiming to have data exfiltrated from 32 million Bumble users.
The post’s author included 27 sample records showing users’ personal data to back up their claims.
At the time, our research team investigated the attackers’ claims and remained skeptical, noting that it was impossible to verify how many users were exposed because the malicious actors had only revealed 27 records.
Bumble didn’t issue a comment on the matter. Also, the attackers’ forum profile was recently created, which is often an indication of a throwaway account.
Another red flag was also the relatively low price for the dataset, which allegedly includes nearly all Bumble users. It is not uncommon for attackers to brag and use well-known names to boost their reputation.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Are these claims related?
The answer is currently unclear. Cybernews researchers found that the dating profile field names in the 2 listings match, suggesting that both datasets may have been structured in a similar way.
However, the earlier listing contained password hashes, while the newer dataset does not appear to include them.
The timestamps are also different. The June listing contained older information, while samples from the new dataset include timestamps extending into August 2026.
Our researchers believe there is a possible scenario in which the newer dataset was collected using the same method as the earlier one, with certain fields subsequently removed or redacted. But there is not enough evidence to confirm that theory.