Platform · Porn addiction recovery support · Behavior change and accountability platform · Global
Mobile app that helps users reduce or quit pornography use and track their recovery progress.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
In February 2026, the pornography-addiction recovery app Quitbro (developed by Plantake) suffered a data breach that exposed roughly 23,000 (22,874) unique email addresses. Beyond emails, the circulating data included users’ years of birth, usernames, their responses to in-app questions about pornography use, and their last recorded relapse timestamps. The developer did not respond to inquiries. The dataset was catalogued by Have I Been Pwned (flagged sensitive and non-searchable) and cross-listed by Hashes.org. No threat actor or attack vector has been reliably established.
Full threat analysis, exploitation vectors, and principal guidance below.
10 additional sections · verified field analysis · defensive doctrine
23K records analyzed
Quitbro is a mobile self-help application developed by Plantake, designed to help users reduce or quit pornography use. It provides habit tracking, streak and relapse logging, in-app questionnaires, and accountability features aimed at behavior change, serving a global base of individuals working on personal recovery goals.
Behavior-change and accountability platforms collect emails, usernames, progress tracking, support interactions, and highly sensitive behavioral information tied to pornography use, recovery goals, and personal struggles.
Quitbro remains available through mobile app stores. Following the February 2026 exposure of user data, its developer Plantake did not publicly respond to inquiries about the incident, drawing criticism over vendor transparency. Have I Been Pwned flagged the breach as sensitive and non-searchable.
The exposure tied real email addresses to deeply stigmatizing behavioral data, including admissions of pornography use and relapse timestamps, for roughly 23,000 users. Even without financial or identity data, appearing in this dataset creates acute risk of extortion, shame-based targeting, and reputational or relational harm, and the developer’s silence compounded the loss of user trust.
• Sextortion and shame-based extortion using admissions of pornography use and relapse data | • Reputational, relational, and employment harm from linkage of email to platform membership | • Targeted harassment and psychological manipulation exploiting recovery struggles | • Targeted phishing using exposed email addresses | • Identity linkage and profiling combining email, username, and birth year
An intimate-data breach: preferences, orientation or explicit content linked to an identity create acute coercion and blackmail exposure. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation