Two AI companion applications, namely 'Chattee Chat – AI Companion' and 'GiMe Chat – AI Companion', fell victim to security flaws, leading to the unauthorized disclosure of data belonging to 400,000 users. This breach encompassed over 43 million private messages, along with more than 600,000 images and videos. Developed by Hong Kong-based Imagime Interactive Limited, these apps, despite the company's assertions of placing a premium on privacy safeguards, were compromised due to a Kafka Broker instance that was leaked and lacked proper access control and authentication protocols. The leaked data encompasses user IP addresses and unique device identifiers, potentially allowing attackers to link them to specific individuals. Furthermore, the exposure of authentication tokens raises the specter of account hijacking. At present, the affected instance has been taken offline; however, it remains unclear whether hackers have already gained access to the data, which could be exploited for malicious activities such as sexual extortion and targeted phishing attacks. There have indeed been prior instances of Kafka instances being exposed, prompting researchers to emphasize the necessity of implementing fundamental security measures. Users should also bear in mind that interactions with AI companions are not entirely confidential. This incident serves as a stark reminder to the AI companion sector, urging relevant companies to institute robust and transparent usage guidelines to protect user privacy.
