Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
A data incident associated with My Lovely AI user identifiers, prompts, and generated-media links. [3]
Impact
A verified HIBP corpus associated with user email addresses, social profiles, prompts, and generated-image links. [2][3]
Documented data types include:
- Usernames and account identifiers — Social-media profiles listed by HIBP, including a small number of Discord and X usernames described in the corpus summary. [3]
- Contact information — Email addresses listed in the HIBP corpus. [3]
A cited record reports 106,271 records (Unique email addresses represented in the verified HIBP corpus; not a company-confirmed number of users, people, prompts, images, files, or total database rows; as of 2026-04-08). [2][3]
HIBP described the associated data as including user-created prompts and links to resulting AI-generated images. [3]
A MyLovely.ai spokesperson said the company was aware of the reports and that no passwords, payment data, or other information it characterized as critical or highly sensitive was leaked. [1]
Timeline
Documented event
HIBP BreachDate; not established as an exact intrusion, detection, containment, or publication date by My Lovely AI.
[3]Public disclosure
Date Malwarebytes published its public report; not a company-notification date.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
Malwarebytes reported that a JSON database was posted on a dark-web forum. [2]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
