Tea App: 13,000 Photos Leaked After Users Tricked Into Giving Up Verification Codes

The Tea app marketed itself as a tool for safety and background checks but ended up being the target of a mass social engineering campaign.
What Happened
In mid-July, users of the Tea app, a social photo sharing platform, were targeted in a coordinated campaign launched via 4chan. The attackers didn’t need to exploit any technical vulnerability in the app. Instead, they relied on mass social engineering.
(4chan is an anonymous message board where users can post without accounts. It has been a launch point for past leaks and cyber incidents.)
Users received a standard SMS verification code from Tea, usually triggered by the attacker submitting a login or signup request using that user’s phone number or email. Attackers then contacted the user, pretending to be a representative from Tea or used phishing websites that mimicked the Tea login page. Once users entered or shared the verification code, attackers gained full access to their accounts.
The attack used:
- No malware
- No backend breach
- Just large-scale abuse of SMS verification flow
What Was Leaked
Over 13,000 private photos were extracted from these accounts and posted online. Many of the users affected were teenagers. The leaked content was sorted into folders by name and gender and uploaded to public file-sharing sites.
What We Know
- SMS verification on its own is not secure enough. It’s vulnerable to phishing, impersonation, and social engineering.
- Tea had no rate limiting or abuse detection in place to prevent mass verification attempts.
- The platform also lacked post login alerting or 2FA layering, which could have reduced account abuse.
Any platform that relies solely on SMS codes for account access, especially with younger users, are exposed. These codes should be treated like passwords and should not be shared under any circumstance.
Co-op: 6.5 Million Members Had Their Data Stolen
The UK based Co-op Group confirmed this month that all 6.5 million of its members had their data compromised in a cyberattack. While full technical details were not disclosed, the incident shares strong similarities with methods used by the group Scattered Spider.

The Co-op storefront in the UK, where retail stores were impacted by the recent cyberattack.
What Happened
Attackers bypassed Co-op’s internal authentication systems, likely through social engineering. Reports suggest that support centre staff were manipulated into resetting access credentials for Co-op systems.
Scattered Spider is known for these tactics. They impersonate IT staff or use deepfake voice calls to convince internal support agents to provide account access or reset multi-factor authentication. In this case, the attackers appear to have successfully accessed member data without deploying malware or exploiting a software vulnerability.
Want to know how attackers are really getting in? Join our live webinar unpacking Scattered Spider’s tactics, tools, and impact across Australia. 6th August 2025 | 12:00PM AEST | Register now
What Was Exposed
Co-op confirmed that the exposed personal information includes:
- Names
- email addresses
- membership numbers
- possibly address data
The organisation has not clarified whether financial information or loyalty data was affected.
What We Know
- The attack likely followed a support centre manipulation model seen in cyber crime groups like Scattered Spider.
- Verification procedures at the helpdesk level were either weak or bypassed
- There is no confirmation that MFA or internal access controls were enforced
- Incident detection was delayed, with all members impacted before containment
Co-op runs supermarkets, funeral care, and legal services across the UK, and the breach disrupted core operations. Some stores reported empty shelves and customer systems went offline for days.
Gridware previously broke down Scattered Spider’s methods in this article and we continue to see similar tactics applied across multiple sectors. If you want a clearer picture of how these attacks unfold and what businesses can do to respond faster, our upcoming webinar on Scattered Spider will give you everything you need to know.
Allianz Life: Customer Data Compromised in Targeted Cyberattack
Earlier this month, Allianz Life in the United States confirmed a data breach that exposed customer information through unauthorised access. Allianz Australia has not been impacted, as it operates under a separate structure and data environment.
The breach appears to have involved credential abuse or unauthorised system access, although full technical details have not been released in an official statement yet.

The Allianz Life headquarters in the US, where the breach affected customer account data. Australian operations were not impacted.
What Was Accessed
- Full names
- Contact details
- Policy or account numbers
- Social Security Numbers (for US customers)
What to Know
- The breach did not involve Allianz Australia.
- Australian systems follow different regulatory and infrastructure requirements.
- Attacks like this often begin with a compromised employee account or third-party access.
Offshore incidents like this are worth knowing about. They show why the community’s most trusted services remain high value targets, and why access controls and breach detection are needed, even for regulated sectors.
58-Year-Old Manufacturer Shuts Down After Ransomware Attack
Earlier this month, a Pennsylvania-based manufacturing company was forced to shut down permanently after a ransomware attack brought operations to a halt. The business had been running for 158 years and employed over 700 people. All jobs were lost following the incident.

The manufacturer’s fleet now sitting idle, after a ransomware attack forced the permanent shutdown of operations.
The attackers reportedly gained access through a single compromised account. The password used was “[Spring2024!]” and had no multi-factor authentication enabled. Once inside, ransomware spread quickly across internal systems, locking staff out and halting production.
KNP investigated the ransomware demand with the help of a specialist firm, which estimated that the monetary demands could be as high as £5 million ($6.74 million). This was a sum beyond the means of KNP, the documentary noting the company “simply didn’t have the money.”
KNP was unable to recover and opted to shut its doors rather than pay the ransom or attempt a rebuild.
What We Know
- Entry was gained through a weak password with no MFA
- Attackers deployed ransomware and locked the company out of core systems
- All operations were shut down, and 700 employees were made redundant
- The business declined to pay the ransom and ceased trading shortly after
While it’s easy to assume no one would ever guess your password, that’s exactly how this breach began. Weak credentials are one of the most common entry points for ransomware, even for businesses that have operated for generations. But their shutdown wasn’t inevitable. With the right support, businesses can keep control and respond with a clear plan rather than reacting under pressure.
July 2025: When Hackers Take the Easy Way In
All the incidents this month point to the same thing. Attackers are still relying on the simplest weaknesses. Guessed or stolen MFA codes, passwords and support centre manipulation are proving more effective this month than technical exploits.
Businesses that delay basic controls are giving attackers a way in. The most common threats right now are the ones that feel too simple to worry about. That’s what makes them dangerous.
If you need support investigating an incident, containing it quickly, or planning for the next one, Gridware’s Digital Forensics & Incident Response team can help.




