HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Grindr Settles $35M Lawsuit Over Unauthorized Sharing of HIV Status and Sensitive Data

Grindr agreed to a £26 million settlement after a UK lawsuit alleged it disclosed users' HIV status and other health details to advertisers without consent. The case underscores the need for auditable consent‑management and continuous privacy‑control monitoring for compliance readiness.

Verisq™ Intelligence · 📅 September 09, 2026 · 📰 malwarebytes.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Grindr Settles $35 M Lawsuit Over Unauthorized Sharing of HIV Status and Sensitive Data

What Happened – Grindr agreed to pay roughly $35 million to settle a UK privacy lawsuit alleging that, between 2018‑2020, the app disclosed users’ HIV status, test dates, PrEP usage, ethnicity and other identifiers to advertising partners without valid consent. The claim was brought on behalf of about 12,000 UK users and follows a similar enforcement action in Norway.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of privacy‑control gaps when third‑party advertising SDKs receive granular user data without a lawful basis.
  • Highlights the need for continuous consent‑management monitoring and auditable evidence that data‑sharing practices align with GDPR‑style obligations.
  • Shows how a single control failure (lack of consent verification) can trigger large financial penalties and erode user trust.

Who Is Affected – Consumer‑tech and dating‑app providers, advertising networks, and any organization that processes health‑related or other highly sensitive personal data.

Recommended Actions

  • Conduct a privacy‑impact assessment focused on third‑party data flows and consent capture.
  • Map your consent‑management process to the GDPR “lawful basis for processing” control and collect evidence (policy docs, logs, UI screenshots).
  • Implement continuous monitoring of SDK integrations and enforce a vendor‑risk program that validates privacy safeguards before data is shared.

Technical Notes – The alleged sharing leveraged advertising SDKs that collected device identifiers, location, IP address and event data, then combined them with self‑reported health information. No software vulnerability was cited. Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/privacy/2026/09/grindr-settles-hiv-status-data-sharing-lawsuit-for-35-million

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →