OkCupid and Match Group Americas: OkCupid, Match Group settle with FTC over unlawful data sharing with AI firm

OkCupid and Match Group Americas: OkCupid, Match Group settle with FTC over unlawful data sharing with AI firm

OkCupid Settles with FTC Over Unauthorized Data Sharing with AI Firm

OkCupid and its parent company, Match Group Americas, have reached a settlement with the Federal Trade Commission (FTC) following allegations that the dating app improperly shared users' sensitive data with an AI solutions firm, Clarifai. According to the FTC, OkCupid granted Clarifai unrestricted access to nearly 3 million user photos, along with demographic and location data, without obtaining consent or offering an opt-out option. The agency linked the incident to OkCupid’s original founders, who had invested in Clarifai.

While OkCupid and Match have not admitted liability, the proposed settlement includes a 20-year legal order that would prohibit the companies from misrepresenting their data collection, storage, and sharing practices. If approved, the order would also mandate clearer disclosures about how sensitive user information including messages, health details, photos, videos, audio files, and location data is handled. The FTC’s restrictions would apply only to OkCupid and Match Group, excluding other Match-owned platforms like Hinge and Tinder.

Source: https://www.scworld.com/brief/okcupid-match-group-settle-with-ftc-over-unlawful-data-sharing-with-ai-firm

Match Group cybersecurity rating report: https://www.rankiteo.com/company/matchgroup

OkCupid cybersecurity rating report: https://www.rankiteo.com/company/okcupid.com

"id": "MATOKC1775017551",
"linkid": "matchgroup, okcupid.com",
"type": "Breach",
"date": "3/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Nearly 3 million users',
                        'industry': 'Online Dating / Social Media',
                        'location': 'United States',
                        'name': 'OkCupid',
                        'type': 'Dating App'}],
 'data_breach': {'data_exfiltration': 'Yes (shared with Clarifai)',
                 'file_types_exposed': ['Photos', 'Videos', 'Audio files'],
                 'number_of_records_exposed': 'Nearly 3 million',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (sensitive personal information)',
                 'type_of_data_compromised': ['Photos',
                                              'Demographic data',
                                              'Location data',
                                              'Messages',
                                              'Health details',
                                              'Videos',
                                              'Audio files']},
 'description': 'OkCupid and its parent company, Match Group Americas, reached '
                'a settlement with the FTC following allegations that the '
                "dating app improperly shared users' sensitive data with an AI "
                'solutions firm, Clarifai. OkCupid granted Clarifai '
                'unrestricted access to nearly 3 million user photos, along '
                'with demographic and location data, without obtaining consent '
                'or offering an opt-out option.',
 'impact': {'brand_reputation_impact': 'Likely negative impact due to FTC '
                                       'settlement',
            'data_compromised': 'Nearly 3 million user photos, demographic and '
                                'location data',
            'identity_theft_risk': 'Potential risk due to exposure of '
                                   'sensitive data',
            'legal_liabilities': 'FTC settlement and 20-year legal order'},
 'investigation_status': 'Settled',
 'motivation': 'Data monetization / AI training',
 'post_incident_analysis': {'corrective_actions': 'FTC-mandated disclosures, '
                                                  'prohibition on '
                                                  'misrepresenting data '
                                                  'practices, and ongoing '
                                                  'compliance monitoring',
                            'root_causes': 'Lack of user consent, improper '
                                           'data sharing practices, and '
                                           'potential conflicts of interest '
                                           "(founders' investment in "
                                           'Clarifai)'},
 'recommendations': 'Implement stricter data sharing policies, obtain explicit '
                    'user consent, and enhance transparency in data handling '
                    'practices.',
 'references': [{'source': 'FTC'}],
 'regulatory_compliance': {'legal_actions': 'FTC settlement and 20-year legal '
                                            'order',
                           'regulations_violated': 'FTC regulations on data '
                                                   'privacy and consent'},
 'response': {'remediation_measures': 'Settlement with FTC, clearer '
                                      'disclosures about data handling'},
 'threat_actor': 'OkCupid (internal misconduct)',
 'title': 'OkCupid Settles with FTC Over Unauthorized Data Sharing with AI '
          'Firm',
 'type': 'Unauthorized Data Sharing'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.