---
title: "My Lovely AI user-content data incident"
description: "Evidence-backed account of My Lovely AI user-content data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/my-lovely-ai-user-content-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/my-lovely-ai-user-content-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/my-lovely-ai-user-content-data-incident-2026/stix.json"
---

# My Lovely AI user-content data incident

A data incident associated with My Lovely AI user identifiers, prompts, and generated-media links. A verified HIBP corpus associated with user email addresses, social profiles, prompts, and generated-image links.

Last modified Aug 9, 2026 · 3 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

A data incident associated with [My Lovely AI](https://www.mylovely.ai/) user identifiers, prompts, and generated-media links. [3](#source-3)

## Impact

A verified HIBP corpus associated with user email addresses, social profiles, prompts, and generated-image links. [2](#source-2) [3](#source-3)

Documented data types include:

- Usernames and account identifiers — Social-media profiles listed by HIBP, including a small number of Discord and X usernames described in the corpus summary. [3](#source-3)
- Contact information — Email addresses listed in the HIBP corpus. [3](#source-3)

A cited record reports 106,271 records (Unique email addresses represented in the verified HIBP corpus; not a company-confirmed number of users, people, prompts, images, files, or total database rows; as of 2026-04-08). [2](#source-2) [3](#source-3)

HIBP described the associated data as including user-created prompts and links to resulting AI-generated images. [3](#source-3)

A MyLovely.ai spokesperson said the company was aware of the reports and that no passwords, payment data, or other information it characterized as critical or highly sensitive was leaked. [1](#source-1)

## Timeline

### April 7, 2026 — Documented event

HIBP BreachDate; not established as an exact intrusion, detection, containment, or publication date by My Lovely AI. [3](#source-3)

### April 9, 2026 — Public disclosure

Date Malwarebytes published its public report; not a company-notification date. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Malwarebytes reported that a JSON database was posted on a dark-web forum. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

HIBP classified the verified corpus as sensitive. The evidence ledger retains 1 disputed claim with the original citations rather than silently resolving the conflict. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [2](#source-2) [3](#source-3)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/my-lovely-ai-user-content-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### MyLovely.ai data breach allegedly leaks 70,000 explicit user prompts, company says nothing critical was exposed

news · SEXTECHGUIDE · Apr 15, 2026

<https://sextechguide.com/ai/mylovely-ai-data-breach-explicit-user-prompts-exposed/>

<a id="source-2"></a>

### NSFW app leak exposes 70,000 prompts linked to individual users

news · Malwarebytes · Apr 9, 2026

<https://www.malwarebytes.com/blog/news/2026/04/nsfw-app-leak-exposes-70000-prompts-linked-to-individual-users>

<a id="source-3"></a>

### My Lovely AI breach record

advisory · Have I Been Pwned · Apr 8, 2026

<https://haveibeenpwned.com/api/v3/breach/MyLovelyAI>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 90% confidence · current**  
   April 2026 My Lovely AI data breach: My Lovely AI user-content corpus
2. **Exposed Data Category · 90% confidence · current**  
   My Lovely AI user-content corpus: Usernames and account identifiers
3. **Affected Organization · 100% confidence · current**  
   April 2026 My Lovely AI data breach: My Lovely AI
4. **Occurred At · 80% confidence · current**  
   April 2026 My Lovely AI data breach: 2026-04-07
5. **Exposed Record Count · 60% confidence · disputed**  
   My Lovely AI user-content corpus: 106,362 record
6. **Resulted In · 90% confidence · current**  
   My Lovely AI user-content corpus: HIBP described the associated data as including user-created prompts and links to resulting AI-generated images.
7. **Exposed Record Count · 100% confidence · current**  
   My Lovely AI user-content corpus: 106,271 record
8. **Disclosed At · 100% confidence · current**  
   April 2026 My Lovely AI data breach: 2026-04-09
9. **Resulted In · 100% confidence · current**  
   My Lovely AI user-content corpus: HIBP classified the verified corpus as sensitive.
10. **Resulted In · 100% confidence · current**  
   My Lovely AI user-content corpus: A MyLovely.ai spokesperson said the company was aware of the reports and that no passwords, payment data, or other information it characterized as critical or highly sensitive was leaked.
11. **Exposed Data Category · 95% confidence · current**  
   My Lovely AI user-content corpus: Contact information
12. **Resulted In · 75% confidence · current**  
   My Lovely AI user-content corpus: Malwarebytes reported that a JSON database was posted on a dark-web forum.

</details>
