[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fu91atcya1ie3":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":12,"affectedCountUnit":21,"hasEnglishDescription":4,"contentLocale":22,"availableLocales":23,"translations":25,"severity":28,"dataClasses":29,"description":40,"seoTitle":41,"seoDescription":42,"logoUrl":43,"isVerified":44,"isSensitive":4,"isSpamList":44,"isMalware":44,"company":45},"6a45347af1d17e7156ce5f47","calai","Cal AI Alleged Data Exposure","calai.app","2026-03-09T00:00:00.000Z","2026-03-16T07:01:42.000Z",null,"2026-09-19T17:08:19.658Z","2026-07-19T00:03:40.937Z","Third party breach","https:\u002F\u002Fcalai.app\u002F",[16,18],"https:\u002F\u002Fcybernews.com\u002Fsecurity\u002Fcal-ai-data-leak-claims\u002F",2830009,"known","email_identifiers","en",[22,24],"tr",{"en":26,"tr":27},{"slug":7},{"slug":7},"Critical",[30,31,32,33,34,35,36,37,38,39],"Email addresses","Names","Dates of birth","Genders","Usernames","Social media profiles","PIN codes","Health and fitness data","Subscription details","Meal logs","\u003Cp>The Cal AI data leak record is an unverified but sensitive data incident claim dated March 2026, associated with the AI-powered calorie and meal tracking app Cal AI. The record is linked to approximately 2,830,009 users. Data classes include email addresses, names, dates of birth, gender information, usernames, social media profiles, PIN codes, health and fitness data, subscription details, and meal logs.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>In this record, health and behavioral data stand out. When meal records, subscription details, PIN codes, physical goals, and profile information are found together, a detailed profile about the user's lifestyle, health goals, and app habits can be formed. For this reason, the record is marked as sensitive data.\u003C\u002Fp>\u003Cp>Payment card or open password fields are not listed in the record; however, PIN code, health\u002Ffitness data, and meal history are important in terms of privacy. Users should not only focus on account security but also on where the personal health and nutrition information they enter into the app may be used.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The incident date is recorded as March 9, 2026. Security news reports claim that around 3 million user data for Cal AI is involved, and some sources mention an open Firebase-like structure and a 4-digit PIN approach. However, the incident is not official and not at a fully independent verification level; therefore, the record remains unverified.\u003C\u002Fp>\u003Cp>When describing the scope, the attack method or the organization's acceptance should not be written as if it is definite. The current text explains the reported data classes and possible risks in the context of health applications. The match should be taken seriously due to the sensitive data risk, but the verification limit should not be hidden from the user.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>At-risk users may be those who have created a Cal AI account, shared meal records, fitness goals, subscription information, or social profile links. Health, weight, nutrition, and daily habit data are important in terms of personal privacy.\u003C\u002Fp>\u003Cp>This type of data can be used in fake health coaching, subscription renewal, app security, diet plan, or insurance-like social engineering messages. If the PIN code has been reused, there may also be a risk for other applications.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users in the matching field should check their Cal AI account and other applications where they use the same PIN\u002Fpassword pattern. Sensitive health, weight, meal, or subscription information entered into the application should be reviewed; suspicious subscription and payment messages should be verified through the official application.\u003C\u002Fp>\u003Cp>Instead of opening incoming links directly, the user should log in through the known web address or official application of the relevant service. Knowing the caller's name, email, address, order, or profile information does not prove that they are trustworthy. One-time verification codes, payment card information, or account passwords should not be shared in any support conversation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>In health and fitness applications, unnecessary profile fields should not be filled, social media connections should be limited, and personal health data should only be stored in services with reliable storage policies. Institutional users should not transfer employee health data to consumer applications.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is present in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result means a match that carries a risk of unverified but sensitive health\u002Ffitness data. A negative result means there is no match within this record; the same email should also be checked in other health or AI applications.\u003C\u002Fp>","Cal AI Alleged Data Exposure (2.8 Million Email Identifiers)","Cal AI Alleged Data Exposure. 2.8 Million email identifiers are reported. Reported data: Email addresses, Names, Dates of birth. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fcalai_app.png",false,{"name":46,"sector":47,"country":48,"website":9,"websiteArchiveUrl":49,"websiteStatus":49,"websiteCheckedAt":12},"Cal AI","Health \u002F Fitness AI","United States",""]