[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1yd9vzb4cm9vy":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":12,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":13,"affectedCountUnit":21,"hasEnglishDescription":4,"contentLocale":22,"availableLocales":23,"translations":25,"severity":28,"dataClasses":29,"description":33,"seoTitle":34,"seoDescription":35,"logoUrl":36,"isVerified":4,"isSensitive":4,"isSpamList":37,"isMalware":37,"company":38},"6a452308a20f867c8ba8e756","My Lovely AI","My Lovely AI Data Breach","my-lovely-ai","mylovely.ai","2026-04-07T00:00:00.000Z","2026-04-08T03:40:14.000Z",null,"2026-07-19T00:03:02.784Z","Verified sensitive adult AI platform breach","https:\u002F\u002Fwww.helpnetsecurity.com\u002F2026\u002F04\u002F09\u002Fmylovely-ai-data-breach-user-conversations\u002F",[16,18],"https:\u002F\u002Fsecurityboulevard.com\u002F2026\u002F04\u002Fnsfw-app-leak-exposes-70000-prompts-linked-to-individual-users-2\u002F",106271,"known","unknown","en",[22,24],"tr",{"en":26,"tr":27},{"slug":9},{"slug":9},"High",[30,31,32],"Email addresses","Social media profiles","AI prompts","\u003Cp>The My Lovely AI data breach is a confirmed sensitive data incident on the adult content AI companion platform My Lovely AI, confirmed on April 7, 2026. The verified scope includes 106,271 accounts. The main exposed data types are email addresses and social media profiles; incident reports also indicated that prompts created by users and links to images generated from these prompts were included in the dataset. Since fields such as passwords, payment cards, physical addresses, or identity documents were not verified, this record should not be directly considered a financial information or password leak. The main risk is that the email address can be interpreted alongside sensitive platform usage, AI prompts, and social profile traces.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The core data types verified in this record are email addresses, social media profiles, and content traces associated with AI prompts. An email address alone is not proof of account takeover; however, when matched with a sensitive adult content platform, it can directly affect the user's reputation, privacy, and online security. Social media profile names, especially on platforms like Discord or X, increase the risk of account matching for individuals using the same identity. Links pointing to user prompts and generated visuals can lead to sensitive inferences about a person's private preferences, fantasies, speech style, or interest in visual content. Therefore, even if the record does not include passwords, it is a high-privacy record that carries risks of blackmail, targeted harassment, fake support messages, and pressure via social profiles.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified incident date should be kept as April 7, 2026, the record addition date as April 8, 2026, and the number of affected accounts as 106,271. The platform domain name is verified as mylovely.ai. The main data classes are email addresses and social media profiles; additionally, AI prompts entered by the user and generated visual content links are also included in the incident. In this record, password, password hashes, phone number, home address, payment card, ID number, or medical data fields have not been verified. This limitation is important: no financial or identity data claims that would cause unnecessary panic to the user are added, but due to adult content and personal prompt context, sensitive data class is maintained. The portion of the scope verified with high confidence is limited to 106,271 accounts.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>In the highest risk group, there are people who open a My Lovely AI account with their primary email address, use the same username on social media accounts, or leave traces that could associate adult content preferences with their real identity. For users who register with a corporate email, the risk is not limited to privacy alone; attackers can lure the user into payment, link clicking, or account verification traps through threat, embarrassment, or fake security alert messages sent to the work email. Users whose social media profiles are visible can be targeted with the threat of exposing their private life to family, work colleagues, or friends. If the same email address has been used in other forums, adult content sites, dating, or AI services, the risk of profile matching increases.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The user who sees a match should first check the security of the relevant email account, ensure that they are using a strong and unique password for the email account, and enable two-factor authentication. Since a password leakage has not been confirmed in this case, one should not conclude that all accounts have been compromised based solely on this record; nevertheless, sensitive accounts using the same email should be reviewed individually. If the same username is used on Discord, X, and similar social profiles, visible profile information should be minimized, message settings tightened, and links from unknown people should not be opened. Messages containing fees for data deletion, account closure charges, visual sharing threats, or embarrassing messages should not be responded to; payments, verification codes, or additional personal information should not be shared.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>This incident shows that accounts used in adult-oriented artificial intelligence and chat services carry a broader privacy risk than classic password security. Users should use separate or masked email addresses instead of their main email on sensitive platforms, avoid reusing social media usernames, and keep profile photo, biography, location, or link fields simple in a way that makes it difficult to match them with their real identity. It should be assumed that generated content links may be permanent, and the possibility of being seen by third parties should be considered when entering private prompts. Organizations should treat the visibility of employee emails in such sensitive records as a security and support issue rather than a disciplinary matter, and provide a clear reporting channel for risks such as blackmail, targeted phishing, and social pressure.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>Seeing a match with My Lovely AI in this record indicates that the relevant email address may be included in sensitive adult content AI platform data dated 2026. The match does not prove that the password, payment card, or identification document has been exposed; the verified risk email address, social profile traces, AI prompts, and generated content links together can compromise the person's privacy. The user should list social profiles and sensitive platform accounts associated with this email address, reduce visible usernames, save incoming threat messages without responding, and keep two-factor authentication enabled on critical accounts. For institutions, the record should be classified not as a password incident but as sensitive account data carrying high privacy and blackmail risk.\u003C\u002Fp>","My Lovely AI Data Breach (106.3 Thousand Reported Records)","My Lovely AI Data Breach. 106.3 Thousand reported records are reported. Reported data: Email addresses, Social media profiles, Ai prompts. Review the scope…","\u002Fuploads\u002Flogo\u002Fmylovely_ai.webp",false,{"name":7,"sector":39,"country":40,"website":10,"websiteArchiveUrl":41,"websiteStatus":41,"websiteCheckedAt":13},"Adult AI Companion \u002F Generative AI","Global",""]