LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Cuties AI Data Breach (2025)

MEDIUM severityConfirmedHow we verify

Cuties AI Data Breach (2025): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·March 21, 2025

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Cuties AI Data Breach (2025)

Reported March 21, 2025. Approximately 144K people affected.

MEDIUM
Severity
144K
People affected
3
Data types exposed
March 21, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Cuties AI disclosed a data breach on 21 March 2025 affecting 144 000 users, exposing their avatars, display names, and email addresses. Anyone who created an account with the service should verify whether their information was exposed and consider changing passwords or enabling additional account protections.

Severity & verification
MEDIUM severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Cuties AI Data Breach (2025) breach?
144K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For roughly 144,000 people who used Cuties AI, personal account details and material tied to private adult image generation may now sit in a public dump. That exposure can turn a once-private preference or creative prompt into something searchable, linkable to an email address, and usable for further targeting or embarrassment.

Public records describe a data breach at the NSFW AI companion platform that was later posted to a public hacking forum. The known scale is 144,000 unique email addresses together with associated profile and generation data. Exact timing of the intrusion itself remains limited beyond the reported window, yet the practical consequence for affected users is immediate: their contact details and content-related information are no longer confined to the service.

Inside the incident

According to the available breach record, Cuties AI experienced a data breach that was subsequently published to a public hacking forum. The incident is associated with a report date of March 21, 2025, while the accompanying summary places the event in March 2026; public detail does not resolve the discrepancy or supply a precise intrusion date. The published material is described as containing 144,000 unique email addresses along with display names, avatars, prompts and descriptions used to generate AI adult images, URLs to the generated content, the account that created the content, and a stated preference of either female or trans. No further technical indicators, such as the initial access method or the duration of unauthorized access, are disclosed in the record. The data appeared in a form that made the listed fields available for download or inspection by anyone visiting the forum post.

How a breach like this happens

Incidents of this type commonly begin with an exposed interface, a compromised credential, or a misconfigured storage location that allows an unauthorized party to copy user tables or content metadata. Once obtained, the data is often packaged and offered on public forums either for notoriety, sale, or free distribution. Attackers may scrape generation logs, profile fields, and associated media links without needing to decrypt every record if those fields were stored in clear text or lightly protected. No specific threat group is named in connection with this event, and the precise vector used against Cuties AI remains undisclosed. In general, platforms that store user-generated adult content and account preferences face elevated risk because the combination of identity data and sensitive creative material increases both the attractiveness of the target and the potential harm if the material is released.

About Cuties AI

Cuties AI operates as an NSFW AI companion platform, a category of service that lets users create and interact with AI-generated adult images and characters. Such platforms typically maintain user accounts, display names, avatar images, free-text prompts that describe desired content, and links to the resulting media. They also often record preference settings that guide generation. Because the service deals in adult material, the data it holds is inherently sensitive; a breach does not merely reveal an email address but can associate that address with explicit creative activity and personal preferences. The consequential nature of a breach here stems from that combination: identity information plus content that many users treat as private.

What was likely exposed

The breach record explicitly names avatars, display names, and email addresses among the exposed fields. The same summary further states that the dump included prompts and descriptions used to generate AI adult images, URLs to the generated content, the account that created the content, and a stated preference of either female or trans. These are the data types reported as present. Exact file formats, whether passwords or payment details were included, and whether every record contained every field remain unconfirmed beyond the listed items. Organisations of this kind commonly retain additional session or usage logs, but those elements are not asserted in the public description of this incident.

Why it matters

For individuals, the primary risks are unwanted contact, social or professional embarrassment, and the possibility that prompts or image URLs could be used to reconstruct or further distribute private material. An email address paired with a display name and adult-content preference can enable targeted phishing or blackmail attempts that reference the leaked details. For the organisation, the release damages user trust and may trigger regulatory scrutiny or contractual obligations, depending on jurisdiction and the nature of the stored data. Because the material was posted publicly rather than held privately by an attacker, the exposure is effectively permanent for practical purposes; once indexed or re-shared, removal becomes difficult.

If your data was in this breach

Begin by changing any password that may have been reused on Cuties AI and enable multi-factor authentication on accounts that share the same email address. Monitor that inbox for unexpected messages that reference adult content or claim knowledge of your preferences. Consider placing fraud alerts with credit bureaus if you used the same email for financial services. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. If you believe you were affected, treat any unsolicited contact that cites the leaked details with caution and avoid engaging until you have verified the source through independent channels.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyCuties AI security record
74/100
DoxxScan™ · Moderate doxx risk
B 80Good record

1 reported incident on record.

See Cuties AI’s full breach history →

More recent breaches

Pass'Sport Data Breach (2025)December 17, 2025APOIA.se Data Breach (2025)December 16, 2025SoundCloud Data Breach (2025)December 15, 2025Under Armour Data Breach (2025)November 17, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Cuties AI Data Breach (2025) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram