The white supremacist dating website WhiteDate suffered a significant data breach in December 2025, resulting in the exposure of over 6,000 unique email addresses and extensive personal information, including physical attributes, income, education, IQ, and more. The breach has been classified as sensitive due to the nature of the data and the potential for adverse impact on affected individuals. Users are advised to check if their information was compromised and to take appropriate security measures, such as using strong, unique passwords.
A self-identified security researcher, Martha Root, claimed responsibility for infiltrating WhiteDate and two related platforms, WhiteChild and WhiteDeal, extracting over 8,000 user profiles and approximately 100 GB of data. The data was published on a site called okstupid.lol and archived by DDoSecrets, making it accessible to the public. The operation involved the use of a custom AI chatbot to automate data collection and social engineering, and the leak included sensitive details such as profile photos, internal communications, and metadata with GPS coordinates. The incident was discussed at the 39th Chaos Communication Congress, highlighting the risks of data reuse and the potential for cross-referencing with other leaks.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
A larger post-breach dataset was later provided to Have I Been Pwned, expanding the known exposure from about 6,100 to 20,000 unique email addresses. Because of the highly sensitive nature of the data, HIBP classified the breach as sensitive and did not make it publicly searchable.
Following the breach, stolen data from WhiteDate and associated platforms was published on okstupid.lol and archived by DDoSecrets. Reports said the leak exposed thousands of user profiles and the affected sites later went offline, with no formal response from the operators.
At the 39th Chaos Communication Congress in Hamburg in December 2025, pseudonymous researcher Martha Root disclosed details of her infiltration of WhiteDate and related platforms WhiteChild and WhiteDeal. She described using a custom AI chatbot to automate data gathering and highlighted weak security on the sites' WordPress infrastructure.
In December 2025, the white supremacist dating site WhiteDate was breached, exposing user data. Compromised information included email addresses, profile details, IP addresses, private messages, and phpBB password hashes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.