AI companion site MyLovely.AI breach exposed explicit prompts
What happened
A breach of AI companion and image platform MyLovely.AI exposed emails, prompts and generated image links for more than 100,000 users. Around 113,000 explicit prompts were included, about 70,000 of them linkable to user IDs, raising sextortion risk.
MyLovely.AI lets users create explicit AI-generated images and videos and chat with AI companions. A 2.1 GB database of its records from April 2026 was posted on a cybercrime forum and added to Have I Been Pwned on 8 April. It held about 106,000 email addresses and user IDs along with account creation dates, subscription levels, a small number of Discord and X usernames, direct links to generated images and videos, content moderation reports, and the exact prompts people typed to create explicit material. Two datasets alone contained about 113,000 explicit prompts, nearly 70,000 of them tied to specific user IDs, which lets someone connect intimate requests to real accounts and raises the risk of sextortion and doxing. How the data was taken has not been disclosed.
How it happened
Unknown: Unknown. No source has explained how the incident happened.
Sources do not say whose AI model was involved. The product was MyLovely.AI, a type of chatbot.
Impact
Data was exposed. Data involved: personal data and chat logs. The impact was confined to one organization and its users or customers. Sources give a figure of 106,362.
Severity is rated Medium, calculated from how far the incident reached and how sensitive the data was.
Was the AI at fault?
No. The failure was in the systems, settings or people around the AI, not in the model's behaviour.
Status and timeline
Reported in the press or by researchers, but not confirmed by the affected organization, the AI vendor or a regulator.
It became public on 8 Apr 2026.
Have I Been Pwned classed the breach as sensitive, so affected users can only check their exposure after verifying their own email address. The company has not publicly commented.