Quitbro 2026 Data Breach

Quitbro Pornography-Recovery App Breach (2026): 23K User Records Including Behavioral & Relapse Data Exposed

Platform · Porn addiction recovery support · Behavior change and accountability platform · Global

Quitbro Pornography-Recovery App Breach (2026): 23K User Records Including Behavioral & Relapse Data Exposed

Mobile app that helps users reduce or quit pornography use and track their recovery progress.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly.
Breach Risk Index i
87/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
23KRecords
2026Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
ViceAdultUsers2026

Breach Summary

In February 2026, the pornography-addiction recovery app Quitbro (developed by Plantake) suffered a data breach that exposed roughly 23,000 (22,874) unique email addresses. Beyond emails, the circulating data included users’ years of birth, usernames, their responses to in-app questions about pornography use, and their last recorded relapse timestamps. The developer did not respond to inquiries. The dataset was catalogued by Have I Been Pwned (flagged sensitive and non-searchable) and cross-listed by Hashes.org. No threat actor or attack vector has been reliably established.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

23K records analyzed

About Quitbro

Quitbro is a mobile self-help application developed by Plantake, designed to help users reduce or quit pornography use. It provides habit tracking, streak and relapse logging, in-app questionnaires, and accountability features aimed at behavior change, serving a global base of individuals working on personal recovery goals.

Why They Hold Your Data

Behavior-change and accountability platforms collect emails, usernames, progress tracking, support interactions, and highly sensitive behavioral information tied to pornography use, recovery goals, and personal struggles.

Recent Developments

Quitbro remains available through mobile app stores. Following the February 2026 exposure of user data, its developer Plantake did not publicly respond to inquiries about the incident, drawing criticism over vendor transparency. Have I Been Pwned flagged the breach as sensitive and non-searchable.

Data Points Exposed

5 verified field types
Behavioral Health Data
Date of Birth High
Email Address
Relapse History
Username

Breach Impact

The exposure tied real email addresses to deeply stigmatizing behavioral data, including admissions of pornography use and relapse timestamps, for roughly 23,000 users. Even without financial or identity data, appearing in this dataset creates acute risk of extortion, shame-based targeting, and reputational or relational harm, and the developer’s silence compounded the loss of user trust.

Exploitation & Downstream Threats

• Sextortion and shame-based extortion using admissions of pornography use and relapse data | • Reputational, relational, and employment harm from linkage of email to platform membership | • Targeted harassment and psychological manipulation exploiting recovery struggles | • Targeted phishing using exposed email addresses | • Identity linkage and profiling combining email, username, and birth year

Principal Risk Advisory

What this means for a principal

An intimate-data breach: preferences, orientation or explicit content linked to an identity create acute coercion and blackmail exposure. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Watch for medical-benefit fraud and health-themed phishing that references real provider relationships.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation