Tea and Fitify apps leak user photos; Proton takes Apple to court; Approov raises £5M to boost API protection - plus key webinar on securing mobile apps.
View in browser
Whats new in mobile security; Approov email header

Subscribe to Approov Newsletter

Summer 2025

Close up of Tea app on smartphone

Tea Dating App Breach Bigger Than Previously Thought

Dating safety app Tea has suffered a major breach exposing approximately 72,000 user images - including 13,000 selfies and ID documents used for account verification - and 59,000 additional images from posts, comments, and direct messages. The exposed content reportedly appeared briefly on 4chan and revealed deeply personal conversations, sparking debate over the app’s infrastructure, data retention policies, and the illusion of anonymity on platforms promising user safety.
(Image credit: Koshiro K - stock.adobe.com)

Read the Full Story and Get Key Security Takeaways

Approov Edinburgh team photo and logo

Approov Secures £5M Series A to Accelerate Mobile App and API Security for the AI Era

Approov has closed a £5 million Series A funding round led by the IFS and Maven Capital Partners, with participation from Souter Investments, Lanza techVentures, and Scottish Enterprise. This funding milestone enables us to bolster our R&D team in
Edinburgh, driving the creation of advanced technologies to secure mobile applications and APIs against evolving threats in real time, including those powered by AI.

Find Out How Approov is Redefining Mobile Security

McDonald’s golden arches logo on a wooden slat background

Image credit: beeboys - stock.adobe.com

McDonald’s Job Applicant Data Exposed via Internal API Flaw

A major flaw in McDonald’s third-party recruitment chatbot exposed sensitive data of over 64 million applicants worldwide. An unauthenticated API allowed access to personal details without login, underscoring the risks of weak API security in outsourced HR platforms.

See How a Simple API Flaw Led to a Massive Data Leak

Conceptual banner of app development

Webinar | August 21: Integrating Mobile Security with Traditional App Sec

Discover how to fully validate every mobile API request and stop fake apps, scripts, bots, and scrapers in their tracks. In this webinar, you'll learn a fast, effective way to authenticate every backend request at runtime - leveraging the app security infrastructure you already have. No major changes. Just better protection, instantly. 

Secure Your Spot Now

Man taking selfie at gym; red overlay

Fitify Fiasco: 138K User Progress Photos Exposed

A fitness app with over 25 million users has accidentally exposed a staggering 373,000 files, including 138,000 progress photos and 6,000 body scans, in an unsecured Google Cloud bucket - no passwords, no encryption, no protection. Even more troubling? Hard‑coded API keys and client secrets for Google, Firebase, Facebook and Algolia lurked in the app’s code, creating multiple attack vectors. 

Don’t Let Your App Be The Next Headline

Glowing Red circuit board shaped like apple held in black gloved hand

Privacy-focused App Maker Proton Sues Apple Over Alleged Anticompetitive Practices and Fees

Proton is suing Apple, alleging anticompetitive practices that harm developers, users, and digital freedoms. The case challenges Apple’s control over app distribution and payments, citing high fees, restrictive rules, and limits on privacy tools. Proton joins a broader class-action push for App Store reform and warns of Apple’s role in enabling censorship. 

See Why Proton Are Pushing Back

Follow Us On LinkedIn
Listen to our podcasts

Approov Limited

US HQ: 165 University Ave.,  Suite 200,  Palo Alto, CA 94301, USA | +1 650 234-5300

UK HQ: 181 The Pleasance, Edinburgh, Midlothian, EH8 9RU, United Kingdom | +44 0131 655 1500

Unsubscribe Manage Preferences