LiveThreat Intelligence Brief — Lovora
What Happened — In February 2026 the Lovora couples‑and‑relationship mobile app suffered a data breach that exposed roughly 496 k unique email addresses, display names, and profile photos. The breach was reported to Have I Been Pwned on 2 Mar 2026; the app’s owner, Plantake, has not responded to inquiries.
Why It Matters for TPRM —
- Personal identifiers (email, name, photo) can be weaponized for credential‑stuffing, phishing, and social‑engineering attacks against users and any downstream services that trust Lovora’s authentication.
- Vendors that integrate Lovora’s API or share user data may inherit the exposure, expanding the attack surface of their own ecosystems.
- Lack of vendor responsiveness signals weak incident‑response governance, a red flag for third‑party risk assessments.
Who Is Affected — SaaS providers in the consumer‑facing tech sector, especially dating/relationship‑app platforms and any partners that exchange user data with Lovora.
Recommended Actions —
- Instruct all users to change passwords on any accounts where Lovora credentials were reused and enable MFA wherever possible.
- Review data‑handling and breach‑notification procedures with Lovora; consider temporary suspension of data exchanges until controls are verified.
- Conduct a risk‑based assessment of downstream impacts on your own customers and update third‑party risk registers.
Technical Notes — The breach appears to be a data‑exfiltration incident likely stemming from a compromised database or mis‑configured storage; no specific CVE or malware was disclosed. Exposed data includes email addresses, display names, and profile photos. Source: https://haveibeenpwned.com/Breach/Lovora