My Lovely AI user-content data incident

A data incident associated with My Lovely AI user identifiers, prompts, and generated-media links. A verified HIBP corpus associated with user email addresses, social profiles, prompts, and generated-image links.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

A data incident associated with My Lovely AI user identifiers, prompts, and generated-media links. [3]

Impact

A verified HIBP corpus associated with user email addresses, social profiles, prompts, and generated-image links. [2][3]

Documented data types include:

  • Usernames and account identifiers — Social-media profiles listed by HIBP, including a small number of Discord and X usernames described in the corpus summary. [3]
  • Contact information — Email addresses listed in the HIBP corpus. [3]

A cited record reports 106,271 records (Unique email addresses represented in the verified HIBP corpus; not a company-confirmed number of users, people, prompts, images, files, or total database rows; as of 2026-04-08). [2][3]

HIBP described the associated data as including user-created prompts and links to resulting AI-generated images. [3]

A MyLovely.ai spokesperson said the company was aware of the reports and that no passwords, payment data, or other information it characterized as critical or highly sensitive was leaked. [1]

Timeline

  1. Documented event

    HIBP BreachDate; not established as an exact intrusion, detection, containment, or publication date by My Lovely AI.

    [3]
  2. Public disclosure

    Date Malwarebytes published its public report; not a company-notification date.

    [2]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Malwarebytes reported that a JSON database was posted on a dark-web forum. [2]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

HIBP classified the verified corpus as sensitive. The evidence ledger retains 1 disputed claim with the original citations rather than silently resolving the conflict. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2][3]