How does this even happen? How can the developers behind an endpoint like this not confirm/test that it requires permissions/authentication to consume? (I mean, look at all that data...) Amateurs I can understand - but OKCupid has been around long enough they shouldn't be employing people of that nature. Is there no code review process? This is just nuts.
And I will tell you on sprints where anyone is busy that team introduces something sloppy or nutty when one of us does not watch closely and ask, sometimes both. But when I point things out people are eager to roll it back.
Never attribute to evil that which comes from ... you get the idea!