Sev0

AI security incidents, tracked

All incidents / Leaky AI product

Sears Home Services AI chatbot databases exposed 3.7 million records

Sears Home Services, disclosed 17 Mar 2026 Leaky AI product Data exposed High

What happened

A researcher found three unsecured databases behind Sears Home Services' AI chatbot and scheduling assistant, exposing chat logs, call recordings, scheduling files and customer personal data. Access was restricted the day after disclosure.

Sears Home Services, the appliance repair business owned by Transformco, uses an AI assistant called Samantha, built on its kAIros platform, to handle scheduling, online chats and phone calls in English and Spanish. Researcher Jeremiah Fowler found three cloud databases with no password or encryption holding records from 2024 to 2026: about 2.1 million text files of scheduling conversations, some 1.4 million audio recordings of customer calls, more than 207,000 spreadsheet logs and one file with 54,359 complete chat transcripts. They contained customers' names, phone numbers, home and email addresses, the appliances they owned and their repair appointments, and the audio could be played in any web browser. Some recordings kept running for up to four hours after customers thought the call had ended, capturing private household conversations and background audio. It is not known how long the data was exposed or whether anyone else accessed it.

How it happened

Leaky AI product: Exposed datastore. A database, storage bucket or server behind an AI product was left open on the internet without a password.

Sources do not say whose AI model was involved. The product was Sears virtual assistant, a type of chatbot.

Impact

Data was exposed. Data involved: chat logs and personal data. The impact was confined to one organization and its users or customers. Sources give a figure of 3,700,000.

Severity is rated High, calculated from how far the incident reached and how sensitive the data was.

Was the AI at fault?

No. The failure was in the systems, settings or people around the AI, not in the model's behaviour.

Status and timeline

Confirmed by the affected organization, the AI vendor, a regulator or a named security research firm.

It became public on 17 Mar 2026.

Fowler reported the databases to Transformco in early February and access was restricted within about a day. The company did not respond to requests for comment from WIRED and has not made a public statement.

Sources

  1. https://www.securitymagazine.com/articles/102188-37m-records-exposed-many-belonging-to-sears-home-services
  2. https://cybernews.com/ai-news/ai-chatbot-data-leak-sears/
  3. https://www.techradar.com/vpn/vpn-privacy-security/expressvpn-uncovers-3-7-million-items-of-leaked-ai-chatbot-data-a-reminder-of-how-vital-encryption-is

Related incidents

Cite as: Sev0, "Sears Home Services AI chatbot databases exposed 3.7 million records", https://sev0.fyi/incidents/2026-03-17-sears-ai-chatbot-databases/. Data for this record: incidents.json.