Not one of the three biggest companion-app leaks required real hacking skill. Either the data sat in the open for anyone who searched, or it was lifted from a site put together with almost no security. That pattern matters more than any single incident.
Three incidents, three different harms

The contents of each leak, based on public reporting.
Muah.ai (2024). An intruder pulled data out of the "AI girlfriend" site and handed it to reporters. Roughly 1.9 million email addresses came with the prompts people typed to generate images. Many were sexual, and some described child abuse. A lot of the addresses pointed to real, identifiable people. Troy Hunt, the security researcher behind Have I Been Pwned, listed it as a sensitive breach, and people in the data later received extortion attempts.
Chattee Chat and GiMe Chat (2025). Cybernews researchers came across a wide-open server with no password, run by the Hong Kong company behind both apps. It held over 43 million messages and more than 600,000 images and videos from about 400,000 users, mostly in the US. No names or emails were in it, but IP addresses, device identifiers and purchase records were, and some users had spent thousands of dollars. The server stayed open until after it had turned up in search engines that index exposed devices.
Secret Desires (2025). Reporters at 404 Media found the platform's cloud storage open to the public. Inside were nearly two million images and videos, many made with a face-swap tool that dropped real women's photos into explicit scenes. Those photos came from social media, graduation pictures and even a yearbook. The company locked the storage roughly an hour after being contacted. We have reviewed Secret Desires, so if you used its image features, this one applies to you.
Why these apps draw attackers
- The material is perfect for extortion. Sexual chats, fantasies and generated images are exactly what blackmailers want.
- Small teams run most of them. A tiny crew shipping fast, sometimes on "duct-taped" open-source parts, tends to skip the basics.
- Nothing gets thrown away. A companion needs your history to remember you, so years of text pile up. See what your AI girlfriend app knows about you.
- Images sit in cloud storage. A misconfigured storage bucket is among the most common causes of leaks anywhere online. Where your generated pictures end up covers how companion apps handle them.
Your checklist if you may be affected
| Order | Action |
|---|---|
| 1. Look up | Enter your email at haveibeenpwned.com; sensitive entries make you confirm the address first |
| 2. Change passwords | Reset the password on the app and on any site where you reused it, and switch on two-factor authentication |
| 3. Break the link | Move the account to an email address that has nothing to do with your name or job |
| 4. Stay alert | Extortion and phishing emails that mention the breach are common in the weeks after |
| 5. Hold the money | Save the messages and report them to the police and the platform; paying rarely stops the demands |
| 6. Images | If intimate pictures are involved, StopNCII.org can help block them on participating platforms |
| 7. Request your file | Ask the company what it holds and demand deletion, as described in how to request your data |

haveibeenpwned.com is free; sensitive entries require you to verify your address.
Limit the fallout before anything happens
- Sign up with a throwaway-style email that doesn't include your name. This one step does the most, since it cuts the tie between the data and your identity.
- Keep your face and identifying details out of image generation and uploads.
- Leave real names out of your chats, particularly partners, coworkers and anyone who appears in an explicit scenario.
- Delete old material. Some apps let you remove single chats or images, and data that no longer exists can't leak. Deleting an AI companion account spells out what really disappears.
- Favor apps that respond to security reports. Mozilla's 2024 review found that 73% of romance chatbot makers said nothing about handling security vulnerabilities. A company with a published security contact at least expects to hear about flaws.
What companies owe you legally
Under EU and UK rules, a company has to tell the regulator about a serious personal data breach within 72 hours, and notify users when the risk to them is high. Most US states also have breach-notification laws. Small offshore operators frequently ignore all of this, so looking yourself up on Have I Been Pwned beats waiting for a message that may never come.
The takeaway from 2024 and 2025 is blunt: intimate data in a companion app is only as safe as the sloppiest engineer on the team. You can't audit that. What you can do is make sure a leak wouldn't lead anyone back to you.