A New Zealand-based company has secured the database information of over 1.5 million users who had registered on various dating site services and the mobile application in which the company operates.
C&Z Tech Limited, the operator of the dating site, secured the database in question after security experts from the Mackeeper Security Research Center alerted the company to the issue.
In an email sent to the MacKeeper team, C&Z said the database only contained test data, an assessment that the MacKeeper team did not believe.
“Thank you for the notification. The MongoDB database was only live for a few hours as we were testing migrating data from SQL to MongoDB, so most of it was just dummy data with random emails and passwords and not our live database. We shut down the database about an hour ago and there is no longer any data breach and it was only you who had detected it.”
C&Z Tech Limited powers many dating sites, such as haveafling.mobi, haveafling.co.nz, haveanaffair.co.nz, haveanaffair.mobi, hookupdating.mobi, as well as some mobile applications.
The MacKeeper team says this database contained the personal information of over 1.5 million users who had registered for these services, which are advertised as websites for finding one-night stands or finding a partner for extramarital affairs.
The MacKeeper team says the data included usernames, plain text passwords, dates of birth, height, weight, gender, body type, race, IP address, country of origin, and other information typically stored on a dating site. None of the C&Z sites displayed any visible security warnings on their websites.
The database is a MongoDB instance, a NoSQL database solution that for some versions a few years back had used a default configuration file that exposed the database to the Internet without a password for the administrator account.
Other dating sites that have suffered data breaches in recent years include Fling.com, Mate1, Beautiful People and Ashley Madison.

