In early April 2026, a breach surfaced at the AI girlfriend and NSFW art-generating platform MyLovely.AI. It wasn’t a major breach in terms of the number of affected users. Only about 106,000 accounts were affected. However, the type of data released and how quickly it ended up on a hacker forum show how even small breaches can cause significant harm, and how the rapidly growing AI companionship space is creating a privacy issue that developers can no longer ignore.
What happened
MyLovely.AI is an AI “girlfriend” and generates NSFW artwork. There are many other similar services (dozens) that grew in popularity during the past two years. Researchers at CyberNews said they validated some sample files posted to a well-known hacking forum to show that a threat actor stated they stole MyLovely.AI’s user database and are selling access to it. Additional analysis by HelpNetSecurity.com and DailyDarkWeb reported that a 2.1GB file (in json format) dated April 2026 was posted to a darkweb forum, which contained information for 106,362 users registered for MyLovely.AI. It was reported as an alleged breach at the time; Have I Been Pwned has since verified and loaded it. Because of what it contains, HIBP has flagged the breach as sensitive, which means it is not publicly searchable — you can only check an address you have verified as your own.
Unlike typical breaches that expose hashed passwords, emails, and possibly a billing address, the MyLovely.AI breach revealed everything a user does on a platform centered on fantasy sex. CyberNews said the leak included:
- Usernames
- Email addresses
- Subscription plans
- Images/video that were generated based upon user requests
- Gallery URLs
- Community posts
- Collections uploaded by users
- Account registration date
- Profile meta-data including:
- Discord handle
- X (Twitter) handle
Most importantly, the leak includes two large databases holding roughly 113,000 explicit requests made to the AI system. About 70,000 of them can be matched to a specific user ID.
For tens of thousands of users, the fantasies they entered privately, and sometimes anonymously, are now public and traceable to a real identity via the email address or social media handle.

How this breach differs from others
Users have become desensitized to data breaches due to their frequency. A leaked password is abstract; you simply change it and forget it. The MyLovely.AI breach disrupts this pattern in three ways.
Firstly, there is the linkability problem. As Malwarebytes noted, once you combine an email address or social media handle with an explicit prompt/request/image, you have enough data to potentially identify a person. Furthermore, if an individual’s work email address is associated with either a pornographic prompt and/or an AI generated image, denial will not be possible. No reasonable individual will believe that this was either a mis-type or misunderstanding; or that a hacker used the same password on another site. This content is specific to your writing style and associated with your username/account.
Secondly, there is the scale of the prompts. If you are embarrassed to find out that you paid money to subscribe to an adult service then being notified of your fantasy content is something much worse. CyberNews’ research team called the leaked NSFW prompts a “gold mine” for malicious actors. They pointed out that, especially in cases involving higher risk individuals, the compromised data could lead to both phishing attacks and potentially more serious sex extortion attempts.
Thirdly, there is the metadata on the platform. MyLovely.AI stored linked Discord and X handles for a minority of accounts, and where they exist an attacker needs no additional detective work to connect a prompt to someone’s broader online presence. That subset is small relative to the whole, but for the people in it the leak is effectively a ready-made contact list.
The Sextortion Formula
Sextortion schemes traditionally rely on intimidation through bluffing. A scammer sends a mass e-mail stating he/she has compromising video material of the recipient and threatens to share it with all of their contacts unless they pay him/her a ransom in cryptocurrency. Due to the fact that most recipients recognize that the attacker has no actual proof of wrongdoing, these e-mails succeed against only a very small percentage of recipients.
The MyLovely.AI breach changes this model. Using an attacker’s copy of the leak, an attacker can now send an e-mail referencing specifically identified prompts entered by the recipient, referencing the recipient’s actual email address used to register, mentioning their connected Discord handle(s), and attaching an AI-generated image copied from the leak. In essence, this e-mail is now evidence that an attacker has actually accessed the recipient’s private correspondence. Recipients who would otherwise laugh at a generalized blackmail attempt may be panicked by seeing their own words staring back at them.
Based on how comparable leaks have been used, two patterns of exploitation are likely. First, there will be rapid-fire automated extortions sent using scripts that personalize the attack using data from the leak. Second, attackers will engage in slow-moving but highly focused harassment efforts directed towards particular victims, primarily those whose email addresses appear to belong to corporations, public figures, or political sensitivities. Victims within these categories pose greater risks to themselves since doxing (the practice of exposing personal identifiable information about someone online without consent) can result in legitimate dangers in jurisdictions where having LGBTQ+ identities, cheating on spouses/fiancés/partners etc., or engaging in any form of sex-related activities can incite legal repercussions or societal consequences.
The Larger Industry Issue
This is not the first AI companion breach, nor will it be the last. Muah.ai exposed roughly 1.9 million records including users’ explicit prompts back in 2024. In October 2025, Cybernews found that two companion apps from one Hong Kong developer, Chattee Chat and GiMe Chat, had left 43 million messages and more than 600,000 images and videos exposed on an unsecured server, affecting over 400,000 users. In February 2026, an independent researcher reached 300 million messages belonging to 25 million users of Chat & Ask AI through a Firebase misconfiguration — the kind of error that requires no hacking skill at all, only the patience to look.
A separate audit by the security firm Oversecured, reported by Cybernews, examined 17 popular AI companion apps on Google Play — collectively downloaded more than 150 million times — and found 14 critical and 311 high-severity vulnerabilities across them.
Similarities exist among all of these incidents. Rapid development occurs to meet massive demand and high profit margins. The time between launching new features typically far exceeds time devoted to developing robust security protocols (retention policies/encryption). Meanwhile, users utilize chat interfaces as virtual confessionals – providing personal identifying information they would never post publicly to social networks – assuming their conversational partner is non-judgmental and non-memorizing.
The MyLovely.AI breach serves as a stark reminder that chat partners DO retain memory, logs ARE retained somewhere, and wherever those logs reside is generally less secure than most users perceive. For the 106K people whose fantasy prompts are currently circulating on Dark Web forums, this lesson came too late. For all remaining users who continue utilizing similar services, the advice is straightforward: don’t register with your primary email address, don’t link your social accounts, and assume anything you type into an AI companion will eventually be read by someone other than that companion.
If you get one of these emails
The advice above helps the people who haven’t been caught yet. If a message referencing your prompts has already landed, a few things are worth knowing.
Don’t pay. Payment marks you as someone who pays, and the demands rarely stop at one. Don’t reply either — engagement confirms the address is live and being read by a person who cares.
Keep the message. Screenshot it, save the headers, note any wallet address. That’s evidence, and deleting it in a panic is the most common early mistake.
Report it. In the US that’s the FBI’s IC3; in the UK, Action Fraud; elsewhere, your national cybercrime reporting line. Reports of this kind are aggregated, and yours is rarely the first.
And check whether you are actually in the leak before assuming the sender has anything at all. Plenty of the messages that follow a publicised breach are sent blind to addresses harvested elsewhere, with the breach name dropped in for credibility. A dark web monitoring service will tell you what has genuinely surfaced against your address, and HIBP will tell you for free whether this particular breach touched you.