惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
N
Netflix TechBlog - Medium
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
V2EX
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Blog — PlanetScale
Blog — PlanetScale
Microsoft Security Blog
Microsoft Security Blog
D
Docker
WordPress大学
WordPress大学
罗磊的独立博客
J
Java Code Geeks
博客园 - 【当耐特】
博客园 - 司徒正美
雷峰网
雷峰网
H
Help Net Security
酷 壳 – CoolShell
酷 壳 – CoolShell
Last Week in AI
Last Week in AI
宝玉的分享
宝玉的分享
Martin Fowler
Martin Fowler
T
Tailwind CSS Blog
Google DeepMind News
Google DeepMind News
M
MIT News - Artificial intelligence
Recent Announcements
Recent Announcements
B
Blog

Malwarebytes

Carnival confirms data breach impacting nearly 6 million Kali365 phishing kit bypasses MFA and steals Microsoft logins Company bragged phone mics could listen to conversations. They couldn’t. Fake LinkedIn emails abuse Adobe to track victims Fake software on GitHub and SourceForge distribute Deno RAT 700+ education and tech websites hijacked in huge ClickFix malware campaign Scammers pretending to be Microsoft had help from US executives A week in security (May 18 – May 24) Update Chrome now: Critical bugs could let attackers run code Microsoft Defender vulnerabilities are being exploited in the wild TikTok, YouTube, and Roblox face scrutiny, but age gates won’t fix child safety Catch spyware in the act with Windows Webcam Monitoring Researchers left AI agents alone in a virtual town and watched it all unravel Fake malware-signing service Fox Tempest dismantled by Microsoft Firefox 151 packs big privacy upgrades into a small update Biometrics, diagnoses, and bank details exposed in major healthcare breach Facebook scam promises cheap Aldi meat boxes, steals payment info instead YouTube wants your face to fight deepfakes Microsoft is changing Edge’s plaintext password behavior A week in security (May 11 – May 17) AI is distorting the Holocaust (Lock and Code S07E10) Attackers replaced JDownloader installer downloads with malware Meta’s confusing new approach to chat privacy Why Malwarebytes blocks some Yahoo Mail redirects Deepfake sextortion forces schools to remove student photos from websites Texas sued Netflix over claims it secretly collected and sold users’ data May 2026 Patch Tuesday: no zero-days but plenty to fix Fake Claude search results lure Mac users into ClickFix attack 1 in 8 employees have sold company logins or know someone who has Stolen Canvas data was “returned” after hacker agreement, Instructure says
NSFW app leak exposes 70,000 prompts linked to individual...
2026-04-09 · via Malwarebytes

MyLovely.AI, an AI “artwork” generation platform, has reportedly been compromised, affecting 106,362 registered users.

The AI girlfriend app allows users to generate personalized NSFW content and engage in real-time conversations with AI-generated personas, often sharing highly personal prompts and interactions.

MyLovely.AI suffered a leak of a 2.1 GB JSON database with records from April 2026 that exposed users’ emails, user IDs, account creation dates, subscription tiers, social profile metadata, explicit images and videos, gallery and community items with direct URLs, and the exact prompts users submitted to generate NSFW content.

The database was posted on a dark web forum, exposing highly sensitive interactions between users and the AI service. Because the leak includes both identifiable information and explicit content, it effectively deanonymizes users’ activity, including highly sensitive sexual content and fantasies.

Two datasets containing 113,000 explicit NSFW prompts were included in the breach, with nearly 70,000 directly tied to unique user IDs. In practice, this means deeply personal requests and interactions can be linked back to individual users.

MyLovely.AI users should expect doxxing and sextortion attempts as a result of the leaked information. Cybercriminals can correlate identifiers— such as email addresses, social media handles, and explicit prompts or images—to real‑world identities, which can be particularly damaging.

Stay safe

This is yet another data breach affecting an AI girlfriend service. Developers tend to rush these emerging platforms into existence because they are popular and profitable. Unfortunately, that often comes at the expense of security and privacy. Here are some things to bear in mind:

  • Don’t trust AI platforms that promise privacy and encryption just because they say so.
  • Don’t log in with your Google/Facebook/Microsoft credentials or by using your regular email address or phone number.
  • Remember that anything you put online, including a service that promises privacy, carries the risk of becoming public.

Despite what users my think when engaging with a chatbot, these conversations should never be considered private. For particularly sensitive use cases (health, sexuality, legal issues), consider services that explicitly commit not to retain or train on conversations.

Check your digital footprint

If you want to find out what personal data of yours has been exposed online, you can use our free Digital Footprint scan. Fill in the email address you’re curious about and get an instant report.


What do cybercriminals know about you?

Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.

About the author

Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.