Grindr agreed to pay £26 million (about $35 million) to settle a UK group action alleging it unlawfully processed and shared sensitive information from users of its free app with third parties before 2020. The claims, brought by law firm Austen Hays on behalf of roughly 12,000 users, concerned data including HIV status, PrEP use, sexual orientation, ethnicity, sex-life information, location, and mental-health details allegedly used for commercial and advertising purposes without adequate consent.
The settlement, reached on September 2 and subsequently disclosed in an SEC filing, does not include an admission or finding of liability. Grindr said the disputed practices occurred while the company was owned and controlled by Kunlun, and said it overhauled its privacy program in 2020. It will pay two £13 million installments by December 31, 2026, and March 31, 2027; the case follows prior UK and Norwegian regulatory scrutiny of Grindr's privacy disclosures and third-party data sharing.

See the reporting duties and controls this puts on the clock.
10 events from the most recent confirmed update back to the earliest known activity.
Grindr disclosed the UK settlement to investors in a US Securities and Exchange Commission filing two days after reaching the agreement.
Grindr agreed to pay £26 million to settle the UK group action over alleged pre-2020 sharing of sensitive data, including HIV-related information. The settlement included no finding or admission of liability, and Grindr continued to dispute the allegations.
Norway's court of appeal upheld the reduced fine imposed on Grindr in the Norwegian GDPR case.
Grindr said it was served with proceedings in the UK group privacy action filed by Austen Hays.
Law firm Austen Hays filed a High Court of England and Wales group action alleging that Grindr shared sensitive user data with third parties without adequate consent. The action concerned free-app users between 2016 and 2020 and represented approximately 12,000 claimants.
The Oslo District Court upheld the Norwegian data-protection penalty against Grindr after the company challenged it.
The UK Information Commissioner's Office reprimanded Grindr for failing to provide UK users with effective and transparent privacy information.
Norway's data protection authority fined Grindr for GDPR violations involving sharing personal data with advertisers without a legal basis. The case concerned data including location, sexual orientation, and mental-health details.
Chinese gaming company Kunlun sold Grindr to San Vicente Acquisition LLC. Grindr later said it overhauled its privacy program following the change in ownership.
Norwegian nonprofit research group SINTEF reported that Grindr shared users' HIV status and last-tested date with app-optimization providers Apptimize and Localytics. Grindr subsequently said it would stop the identified sharing practice.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
8 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcetherecord.media
Open sourcemalware.news
Open sourceinfosecurity-magazine.com
Open sourcethehackernews.com
Open sourcetheguardian.com
Open sourceaustenhays.com
Open sourcesec.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.