HomeIntelligenceBrief
BREACH BRIEF 🟡 Medium Breach

Lovora breach leaks nearly 500k user emails, names, and photos

In February 2026, the couples and relationship app Lovora allegedly suffered a data breach that exposed 496k unique email addresses. The data also included users’ display names and profile photos, along with other personal information collected through use of the app. The app’s maker, Plantake, did not respond to multiple attempts to contact them about the incident.

Verisq™ Intelligence · 📅 March 05, 2026 · 📰 haveibeenpwned.com
🟡
Severity
Medium
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
haveibeenpwned.com

LiveThreat Intelligence Brief — Lovora

What Happened — In February 2026 the Lovora couples‑and‑relationship mobile app suffered a data breach that exposed roughly 496 k unique email addresses, display names, and profile photos. The breach was reported to Have I Been Pwned on 2 Mar 2026; the app’s owner, Plantake, has not responded to inquiries.

Why It Matters for TPRM

  • Personal identifiers (email, name, photo) can be weaponized for credential‑stuffing, phishing, and social‑engineering attacks against users and any downstream services that trust Lovora’s authentication.
  • Vendors that integrate Lovora’s API or share user data may inherit the exposure, expanding the attack surface of their own ecosystems.
  • Lack of vendor responsiveness signals weak incident‑response governance, a red flag for third‑party risk assessments.

Who Is Affected — SaaS providers in the consumer‑facing tech sector, especially dating/relationship‑app platforms and any partners that exchange user data with Lovora.

Recommended Actions

  • Instruct all users to change passwords on any accounts where Lovora credentials were reused and enable MFA wherever possible.
  • Review data‑handling and breach‑notification procedures with Lovora; consider temporary suspension of data exchanges until controls are verified.
  • Conduct a risk‑based assessment of downstream impacts on your own customers and update third‑party risk registers.

Technical Notes — The breach appears to be a data‑exfiltration incident likely stemming from a compromised database or mis‑configured storage; no specific CVE or malware was disclosed. Exposed data includes email addresses, display names, and profile photos. Source: https://haveibeenpwned.com/Breach/Lovora

📰 Original Source
https://haveibeenpwned.com/Breach/Lovora

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →