Researchers have discovered that dating app Heyyo left a server exposed to the internetafter failing to protect it with a password , resulting in the leak of user data.
It is an Elasticsearch serverthat exposed personal information, images, location data, phone numbers, and more. The exposed data belongs to approximately 72,000 users.
The software company behind the app, which is based in Istanbul, was notified of the breach a week ago but did not respond. The server was restored today after being notified by Turkey's Computer Emergency Response Team (CERT).
The server exposed a lot of sensitive data. Unfortunately, the server contained all of the users' information as well as some private messages.
The information that was leaked is: names, phone numbers, email addresses , dates of birth, gender, height, photos, Facebook and Instagram IDs (for users who were logged in from their profile), location data, dating preferences, profiles that users have liked or disliked, profiles that users have blocked, dates of registration and use of the application, and device information

This information is very important and can put application users at risk
Anyone can do a simple search on the internet, and using this information, find the real identities of users, their LinkedIn profiles, accounts . They can even find posts that users have made on various forums.
Furthermore, this data could be used to blackmail users regarding their personal and love lives (since it is a dating app).
It is currently unknown whether anyone gained access to the exposed server and whether the data was used for malicious purposes.
Many other services have been found to have the same problem (with an exposed server). Some of them are: Ashley Madison, Jack'd, Grindr, Romeo, Recon, 3Fun, HaveAFling, HaveAnAffair, HookUpDating and Luscious.
