My Lovely AI Breach Exposes 106K User Prompts
In April 2026, the NSFW AI girlfriend platform My Lovely AI suffered a data breach that exposed over 100k users . The data included user-created prompts and links to the resulting AI-generated images, along with a small number of Discord and X usernames.
Overview
In April 2026, the NSFW AI companion platform My Lovely AI suffered a data breach impacting 106,271 user accounts. The breach exposed sensitive user-generated content, moving beyond basic login credentials to reveal intimate user interactions with the AI service. This incident was confirmed and reported to the breach notification service Have I Been Pwned.
What Was Exposed
The compromised data is particularly sensitive due to the platform’s nature. Exposed information includes:
- Usernames and Names: Basic account identifiers.
- User-Created Prompts: The private text inputs and requests users submitted to generate AI companion interactions and images.
- Links to AI-Generated Images: Direct URLs to the resulting NSFW images created by the AI.
- A Small Number of Discord and X Usernames: For some users, their social media handles were also linked and exposed.
Potential Impact
The exposure of prompts and image links creates significant privacy and safety risks that differ from a standard password leak.
- Extortion and Blackmail: Malicious actors could use the intimate nature of the exposed prompts and image links to threaten or extort users.
- Profiling and Targeted Harassment: The data could be used to build detailed profiles for targeted phishing, doxxing, or harassment on other platforms, especially where Discord or X usernames were linked.
- Embarrassment and Reputational Harm: The public or private revelation of this data could cause severe personal and professional embarrassment.
- Credential Stuffing: While passwords were not reported in this breach, exposed usernames/emails could be used in credential stuffing attacks on other websites.
Recommendations
Affected users should take immediate action to protect their privacy and security.
- Assume Your Data is Public: Operate under the assumption that your prompts and any associated image links are now in the wild. Do not engage with anyone who contacts you claiming to have this data.
- Change Your My Lovely AI Password: If you reused your My Lovely AI password on any other site, change it on those sites immediately. Use a strong, unique password for every online account.
- Be Vigilant for Phishing: Be extremely cautious of any emails, Discord messages, or social media DMs that reference My Lovely AI, your prompts, or seem to know intimate details. Do not click on links or provide any information.
- Review Linked Accounts: If you used a Discord or X username on the platform, review the privacy and security settings on those accounts. Enable two-factor authentication.
How to Check If You’re Affected
You can check if your data was compromised in this breach by visiting the Have I Been Pwned website. Go to haveibeenpwned.com and enter your email address into the search bar. The service will tell you if your email was found in the My Lovely AI breach dataset. You can also view the specific breach entry at https://haveibeenpwned.com/Breach/MyLovelyAI.
Security Insight
This breach highlights the unique data liability of platforms handling deeply personal and intimate user-generated content. Unlike a retailer losing credit card numbers, the exposure of private prompts represents a fundamental breach of user trust and contextual integrity. Companies in the personal AI and adult content space must implement security controls that reflect the severe personal harm this data can cause, a lesson often underscored in broader cybersecurity news. Failing to do so treats sensitive psychological data with the same protection level as a shopping list.
Further Reading
Investigate Breaches Safely with NordVPN
Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.
Get NordVPN for ResearchAffiliate link — we may earn a commission at no extra cost to you.
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In March 2026, the NSFW AI companion platform Cuties AI suffered a data breach that was subsequently published to a public hacking forum . The incident exposed 144k unique email addresses along with display names, avatars, prompts and descriptions used to generate AI adult images, as well as URLs to...
In March 2026, the League of Legends custom skins service Divine Skins suffered a data breach . The incident was disclosed via the service's Discord server, where Divine Skins stated that an unauthorised third party accessed part of its systems, deleted all skins from the database and exposed email ...
In early 2026, data purportedly sourced from the recipe and meal planning service Provecho was alleged to have been obtained in a breach. The exposed data included 713k unique email address along with username and the creator account holders followed. Provecho has been notified and is aware of the c...
In February 2026, the couples and relationship app Lovora allegedly suffered a data breach that exposed 496k unique email addresses. The data also included users’ display names and profile photos, along with other personal information collected through use of the app. The app’s maker, Plantake, did ...