Muah.AI 2024 Data Breach

Muah.AI 'AI Girlfriend' Chatbot Breach (2024): 1.9 Million User Records Including AI Prompt Content & Sexual Preferences Exposed

Platform · AI-driven companion and chat services · Consumer AI platform · Global

Muah.AI 'AI Girlfriend' Chatbot Breach (2024): 1.9 Million User Records Including AI Prompt Content & Sexual Preferences Exposed

AI chatbot and conversational platform.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly. Use the private exposure check at the bottom of this page.
Breach Risk Index i
65/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
1.9MRecords
2024Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
IntimateSexual Preferences
Classification Tags
Cloud MisconfigurationSocial NetworkingChatUsers2024

Breach Summary

Muah.AI, a self-described 'uncensored' AI girlfriend and companion chatbot platform, suffered a data breach on or around September 17, 2024 when a hacker exploited vulnerabilities in the site's infrastructure. The hacker reportedly described Muah.AI's technical foundation to 404 Media as a poorly assembled collection of open-source components and disclosed the breach to journalists after discovering the disturbing content of the user-prompt database. The breach was publicly disclosed in early October 2024 through 404 Media reporting and was indexed by Have I Been Pwned on October 8, 2024 with a sensitive flag. The breach affected approximately 1.9 million users based on records indexed by Have I Been Pwned, which counted approximately 1,910,261 unique email addresses. Compromised fields included email addresses, AI prompts directing image generation, and user sexual-preference settings. The site's email-verification process meant that affected email addresses had been verified by their owners before the prompts were submitted, indicating that the prompts can credibly be tied to real individuals rather than to fraudulent use of someone else's email address. Many of the prompts were highly sexual in nature, and a significant portion of them described child sexual abuse scenarios, including documented requests for AI-generated content depicting infants and young children. The platform's email addresses are largely tied to real personal identities including names visible in LinkedIn profiles, rather than to anonymous burner accounts. For affected users, the practical risk profile is exceptionally severe and varies substantially by the content of individual users' prompts. For users whose prompts were limited to lawful adult content, the standard adult-platform extortion-risk profile applies. Affected users who receive extortion attempts should not pay ransom demands because payment does not stop further extortion. Users should change any reused passwords on other accounts, enable two-factor authentication where available, document all extortion communications, and report extortion attempts to law enforcement. For users whose prompts described child sexual abuse scenarios, the risk profile extends substantially beyond extortion to include direct criminal exposure under U.S., U.K., and other jurisdictions' laws governing the production, possession, or attempted generation of child sexual abuse material, including computer-generated pseudo-images. Users with this exposure may be referred to legal counsel and should expect that law enforcement agencies have access to or are reviewing the breach data. A documented active extortion vector specifically targets high-value IT employees among affected users, demanding access to employer systems rather than financial payment, meaning employers may be at indirect risk through their staff's exposure in this breach.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

1.9M records analyzed

About Muah.AI

Muah.AI is an 'AI girlfriend' companion-chatbot platform that allows users to create and interact with customized AI-powered companions for romantic, sexual, and conversational role-play. The platform offers text chat, voice chat, and AI-generated image exchange with user-customized AI characters described as 'caring AI-powered girlfriends, supportive boyfriends, or virtual therapists.' Muah.AI markets itself as 'uncensored' and explicitly positions itself in opposition to mainstream AI platforms' content moderation, stating publicly that it does not 'actively censor or filter AI' and that 'any topic can be discussed without running into a wall.' As an account-based generative-AI companion platform, Muah.AI maintains user account data including email addresses and stored prompt history that captures users' generative requests, sexual fantasies, fetish preferences, and persistent character-customization settings.

Why They Hold Your Data

AI companion and sexually oriented chatbot platforms collect account emails, generated prompt history, fetish-linked preferences, and interaction data tied to deeply personal or explicit use cases.

Recent Developments

The Muah.AI breach was first reported by 404 Media in early October 2024 after a hacker independently discovered and exploited vulnerabilities in the site's infrastructure. The hacker, who reportedly stumbled onto the vulnerabilities while using the site for adult content, told 404 Media that the platform was 'basically a handful of open-source projects duct-taped together' and that they decided to contact journalists after seeing what was in the database. Have I Been Pwned added the breach on October 8, 2024 with a sensitive-breach designation. Muah.AI's administrator publicly responded by claiming the hack must have been 'sponsored by competitors in the uncensored AI industry' rather than acknowledging the platform's security weaknesses. The breach has been the subject of significant legal and media analysis, including detailed coverage from Linklaters and other law firms regarding criminal exposure for users whose prompts described illegal content, and regarding active extortion attempts targeting affected individuals.

Data Points Exposed

3 verified field types
AI Prompt Content
Email Address
Sexual Preferences High

Breach Impact

The institutional impact on Muah.AI is significant on reputational and regulatory dimensions, although the platform continues to operate. Law enforcement attention has been raised in multiple jurisdictions because of the documented presence of child-exploitation prompts in the dataset, with potential implications for the platform's compliance with content-moderation, anti-CSAM, and AI-safety regulatory frameworks emerging in 2024 to 2026. The case has been cited as a leading example of safety failures in the unmoderated AI-companion category and has shaped subsequent regulatory and platform-policy discussions about generative-AI content moderation. Active extortion campaigns targeting affected users have been documented, including a notable pattern in which threat actors target high-value IT employees in affected user populations, demanding access to employer systems rather than financial ransom. This represents an unusual extortion vector that elevates the breach's institutional impact beyond Muah.AI itself to the employers of affected users.

Exploitation & Downstream Threats

• Targeted phishing campaigns using exposed email addresses

Principal Risk Advisory

What this means for a principal

A social-platform breach: profile and contact-graph data supports impersonation, enrichment and social engineering. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Be alert to sextortion or blackmail attempts referencing this data and do not engage; preserve and report messages.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Protect Yourself: Limited Disclosure

Check If You’re Affected: Verification Required

Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.

We will only reveal whether a specific person appears in this breach to that person.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation