None of the three biggest companion-app leaks required a brilliant attacker. Either the data was lying open for anyone who went looking, or it was stolen from a site that had hardly any protection. Keep that pattern in mind.
Three leaks and what each one cost people

The contents of each leak, as reported.
Muah.ai, 2024. Someone broke into the "AI girlfriend" site and gave the stolen files to reporters. Inside were about 1.9 million email addresses, each tied to the prompts that person had entered to generate pictures. Plenty were sexual and some described child abuse. Many addresses could be traced to real individuals. Troy Hunt, the security researcher behind Have I Been Pwned, listed it as a sensitive breach, and extortion attempts aimed at people in the files came afterwards.
Chattee Chat and GiMe Chat, 2025. A Hong Kong company built both apps. Cybernews researchers found its server exposed with no password at all. It held over 43 million messages and 600,000-plus images and videos from roughly 400,000 users, largely American. Names and emails weren't there, but IP addresses, device IDs and purchase histories were, and those histories showed some users spending thousands of dollars. The server stayed open until after it had shown up on public search engines that index exposed devices.
Secret Desires, 2025. 404 Media journalists discovered that the platform's cloud storage could be viewed by anybody. It contained close to two million images and videos, including a big collection from a face-swap feature that inserted real women's photos, lifted from social media, graduations and even a yearbook, into explicit material. Once the company was contacted, it closed the storage in about an hour. We've reviewed Secret Desires, so if you used its image tools this one concerns you.
What makes these apps attractive to thieves
- Blackmail value. Sexual chats, fantasies and generated pictures are what extortionists dream of.
- Tiny teams. Quick-growing apps run by a few people, sometimes assembled from patched-together open-source parts, often skip basic protection.
- A long paper trail. Remembering you means storing your history, so years of writing accumulate. See what your AI girlfriend app knows.
- Pictures in the cloud. Poorly set-up storage is one of the top reasons for leaks across the internet. Where your pictures actually live covers how companion apps handle it.
What to do if you think you're affected
| Step | Action |
|---|---|
| 1. Search | Enter your email at haveibeenpwned.com; for sensitive breaches you must first verify it |
| 2. Change your locks | Choose a fresh password on the service and every place you reused it, and switch on two-factor login |
| 3. Break the link | Move the account to an email that isn't tied to your name or your employer |
| 4. Expect messages | Blackmail and phishing emails that cite the breach are common in the weeks after |
| 5. Hold your money | Keep everything, report it through ReportCyber (cyber.gov.au) and the platform; paying seldom stops it |
| 6. Pictures | If intimate images are involved, use StopNCII.org and report image-based abuse to eSafety |
| 7. Get support | Worried about identity theft? IDCARE gives free help on 1800 595 160 |
| 8. Push back | Ask what the company holds and request deletion, following how to request your data |

haveibeenpwned.com costs nothing; sensitive breaches ask you to verify the address.
Before anything goes wrong
- Use a throwaway email with no trace of your name. Nothing beats this, because it severs the tie between the data and you.
- Don't upload your own face or identifying details to any app.
- Keep real names out of chats. That covers partners, colleagues and anyone in an explicit scene.
- Clear out old material. Some apps let you remove chats or pictures one at a time, and what's deleted can't be leaked. Deleting an AI companion account explains what is actually wiped.
- Choose apps that discuss security. Mozilla's 2024 review found 73% of romance chatbot makers said nothing about how they handle vulnerabilities. A company with a security contact at least wants to hear about holes.
The rules companies in Australia must follow
The Notifiable Data Breaches scheme, part of the Privacy Act 1988, requires covered organisations to inform the OAIC and the people involved when a breach is likely to cause serious harm. They get 30 days to assess a suspected breach, then must notify as soon as practicable if it qualifies. Small overseas outfits often ignore this, so running your own Have I Been Pwned search beats waiting for a notice. By comparison, the EU and UK give companies 72 hours, and most US states have their own laws.
The uncomfortable lesson from 2024 and 2025: intimate data in a companion app is exactly as safe as the most careless engineer on the payroll. You can't inspect that person's work, but you can make sure a leak wouldn't point back to you.