My Lovely AI Breach Exposes 106K User Prompts
In April 2026, the NSFW AI girlfriend platform My Lovely AI suffered a data breach that exposed over 100k users . The data included user-created prompts and links to the resulting AI-generated images, along with a small number of Discord and X usernames.
Overview
On April 2026, the NSFW AI girlfriend platform My Lovely AI confirmed a data breach affecting 106,271 user accounts. The breach exposed user-created prompts, links to AI-generated images, and a small number of Discord and X usernames. The incident was reported to Have I Been Pwned (HIBP), and affected users can verify their exposure at haveibeenpwned.com.
What Was Exposed
The compromised data includes:
- Usernames: Display names and account identifiers.
- User-Created Prompts: The text inputs users provided to generate AI responses or images. These prompts often contain highly personal, intimate, or identifying details.
- AI-Generated Image Links: Direct URLs to images produced by the platform based on user prompts. These images may depict users or others, and the metadata could reveal locations or devices.
- Discord and X (Twitter) Usernames: A small subset of accounts linked social media profiles, enabling cross-platform identification.
Why This Matters
This breach is unusual because the exposed data goes beyond account credentials-it includes the content users created. Prompts on NSFW platforms often contain sensitive personal fantasies, identifiable descriptions, or even real names and locations. The links to AI-generated images compound the risk, as these images could depict users in compromising situations, and the metadata might expose technical details like file creation timestamps or device identifiers.
Who’s Actually Affected
All 106,271 registered accounts are affected. However, the breach’s impact extends to anyone included in the prompts or images-even if they never used the platform. For example, a user who described a real partner or shared a recognizable image could inadvertently expose that person’s identity or personal details.
How to Check If You’re Affected
- Visit Have I Been Pwned: Go to haveibeenpwned.com and search your email address.
- Look for My Lovely AI: If your email is in the breach, the site will show an entry for this incident.
- Check Your Account: Log in to My Lovely AI and review your saved prompts and images. Delete any content you wish to remove.
- Monitor for Phishing: Be alert for emails claiming to offer “breach support” or requesting personal information-this is likely a scam.
What to Do Right Now
- Change your My Lovely AI password immediately, even if you don’t see your email in HIBP. Use a unique, strong password.
- Review and delete any saved prompts, image links, or associated social media connections on the platform.
- If you shared prompts with real-world details (names, places, identifiable descriptions), consider the risk to those individuals and inform them.
- Enable two-factor authentication (2FA) on any account where you used the same username or email combination.
- Watch for social engineering attempts-attackers may use the exposure of preferences or identity to craft targeted scams.
Security Insight
This breach reveals a critical oversight in platforms handling NSFW user-generated content: storing raw, unencrypted prompts and image links as if they were just metadata. Unlike password hashing, prompt storage often lacks any protection, leaving intimate user data fully readable in a breach. This incident aligns with a broader pattern in adult-tech breaches, where the data’s sensitivity far exceeds its technical exposure. The lesson for developers is clearypt user-generated content at rest, and treat prompt logs as personally identifiable information (PII) because, in many cases, that is exactly what they are.
Further Reading
Investigate Breaches Safely with NordVPN
Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.
Get NordVPN for ResearchAffiliate link — we may earn a commission at no extra cost to you.
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In March 2026, the League of Legends custom skins service Divine Skins suffered a data breach . The incident was disclosed via the service's Discord server, where Divine Skins stated that an unauthorised third party accessed part of its systems, deleted all skins from the database and exposed email ...
In early 2026, data purportedly sourced from the recipe and meal planning service Provecho was alleged to have been obtained in a breach. The exposed data included 713k unique email address along with username and the creator account holders followed. Provecho has been notified and is aware of the c...
In January 2026, the automotive research and car-shopping platform Edmunds was listed by the ShinyHunters hacking group as having been breached . Data purportedly obtained in the incident was later published publicly and included 178k unique email addresses, usernames, passwords, IP addresses, phone...
In May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and published the service's database to a public GitHub repository. The incident exposed 64k unique email addresses along with usernames, IP addresses, suppo...