None of the three largest leaks from AI companion services involved a clever attack. In each case, data was reachable by anyone who knew where to look, or taken from a site built with little security. That is the pattern worth understanding.
Three leaks, three kinds of damage

What was exposed in each case, as reported.
Muah.ai, 2024. A hacker took data from the "AI girlfriend" site and passed it to journalists. It contained about 1.9 million email addresses alongside the prompts users had written to generate images - many sexual, and some describing child abuse. Many addresses were linked to real identities. Security researcher Troy Hunt added the breach to Have I Been Pwned as a sensitive breach, and extortion attempts against people in the data followed.
Chattee Chat and GiMe Chat, 2025. Researchers at Cybernews found a server belonging to the Hong Kong developer of these two apps left open with no password. It held more than 43 million messages and over 600,000 images and videos from around 400,000 users, mostly in the US. There were no names or emails, but there were IP addresses and device identifiers, and purchase logs showing some users had spent thousands of dollars. The server was closed only after it had appeared in public search engines for exposed devices.
Secret Desires, 2025. Journalists at 404 Media found the platform's cloud storage publicly accessible. It held nearly two million images and videos, including a large set made with a face-swap feature that put real women's photos - taken from social media, graduation pictures, even a yearbook - into explicit content. The storage was locked within about an hour of the company being contacted. Secret Desires is one of the apps we have reviewed; the leak is relevant to anyone who used its image features.
Why companion apps are attractive targets
- The content is uniquely compromising. Sexual chats, fantasies and generated images are ideal material for extortion.
- Many operators are small. Fast-growing apps built by tiny teams, sometimes on "duct-taped" open-source components, often skip security basics.
- Everything is stored. The service needs your history to remember you, so years of text accumulate - see what your AI girlfriend app knows.
- Images live in cloud storage. Misconfigured storage buckets are one of the most common causes of leaks across the whole internet. The details of how companion images are stored are in where your pictures actually live.
If you think you were affected
| Step | What to do |
|---|---|
| 1. Check | Search your email on haveibeenpwned.com; sensitive breaches need you to verify the address |
| 2. Lock down | Change the password on the service and anywhere you reused it; turn on two-factor authentication |
| 3. Separate | Move the account to an email address not tied to your name or work |
| 4. Expect contact | Watch for extortion and phishing emails that quote the breach - they are common afterwards |
| 5. Do not pay | Keep the messages, report to the police and the platform; payment rarely ends demands |
| 6. Images | If intimate images are involved, StopNCII.org can help block them on participating platforms |
| 7. Ask | Request what data the company held and ask for deletion - see how to request your data |

haveibeenpwned.com - free to use; sensitive breaches require verifying your address.
Reducing the damage before any breach
- Use a separate email address that does not contain your name. It is the single most effective step, because it breaks the link between the data and you.
- Never put your face or identifying details into generated images or uploads.
- Keep names of real people out of chats, especially partners, colleagues and anyone in explicit scenarios.
- Delete what you no longer need. Some apps let you delete individual chats or images; old data cannot leak if it no longer exists. Deleting an AI companion account explains what actually gets removed.
- Prefer apps that answer security questions. In Mozilla's 2024 review, 73% of romance chatbot makers said nothing about how they handle security vulnerabilities. A company that publishes a security contact is at least expecting to be told about problems.
What the law requires of companies
In the EU and UK, a company must report a serious personal data breach to the regulator within 72 hours and tell affected users when the risk to them is high. Most US states have breach-notification laws too. In practice, small overseas operators often ignore these duties, which is why checking Have I Been Pwned yourself matters more than waiting for an email.
The uncomfortable conclusion from 2024 and 2025 is that intimate data in companion apps is only as safe as the least careful engineer at the company. You cannot audit that - but you can make sure a leak would not lead back to your name.