Connect with us

Technology

Millions of AI chat messages exposed in app data leak

Published

on

Millions of AI chat messages exposed in app data leak

NEWYou can now listen to Fox News articles!

A popular mobile app called Chat & Ask AI has more than 50 million users across the Google Play Store and Apple App Store. Now, an independent security researcher says the app exposed hundreds of millions of private chatbot conversations online. 

The exposed messages reportedly included deeply personal and disturbing requests. Users asked questions like how to painlessly kill themselves, how to write suicide notes, how to make meth and how to hack other apps. 

These were not harmless prompts. They were full chat histories tied to real users.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Advertisement

HOW TECH IS BEING USED IN NANCY GUTHRIE DISAPPEARANCE INVESTIGATION

Security researchers say Chat & Ask AI exposed hundreds of millions of private chatbot messages, including complete conversation histories tied to real users. (Neil Godwin/Getty Images)

What exactly was exposed

The issue was discovered by a security researcher who goes by Harry. He found that Chat & Ask AI had a misconfigured backend using Google Firebase, a popular mobile app development platform. Because of that misconfiguration, it was easy for outsiders to gain authenticated access to the app’s database. Harry says he was able to access roughly 300 million messages tied to more than 25 million users. He analyzed a smaller sample of about 60,000 users and more than one million messages to confirm the scope.

The exposed data reportedly included:

  • Full chat histories with the AI
  • Timestamps for each conversation
  • The custom name users gave the chatbot
  • How users configured the AI model
  • Which AI model was selected

That matters because many users treat AI chats like private journals, therapists or brainstorming partners.

How this AI app stores so much sensitive user data

Chat & Ask AI is not a standalone artificial intelligence model. It acts as a wrapper that lets users talk to large language models built by bigger companies. Users could choose between models from OpenAI, Anthropic and Google, including ChatGPT, Claude and Gemini. While those companies operate the underlying models, Chat & Ask AI handles the storage. That is where things went wrong. Cybersecurity experts say this type of Firebase misconfiguration is a well-known weakness. It is also easy to find if someone knows what to look for.

Advertisement

We reached out to Codeway, which publishes the Chat & Ask AI app, for comment, but did not receive a response before publication.

149 MILLION PASSWORDS EXPOSED IN MASSIVE CREDENTIAL LEAK

The exposed database reportedly included timestamps, model settings and the names users gave their chatbots, revealing far more than isolated prompts. (Elisa Schu/Getty Images)

Why this matters to everyday users

Many people assume their chats with AI tools are private. They type things they would never post publicly or even say out loud. When an app stores that data insecurely, it becomes a gold mine for attackers. Even without names attached, chat histories can reveal mental health struggles, illegal behavior, work secrets and personal relationships. Once exposed, that data can be copied, scraped and shared forever.

YOUR PHONE SHARES DATA AT NIGHT: HERE’S HOW TO STOP IT

Advertisement

Because the app handled data storage itself, a simple Firebase misconfiguration made sensitive AI chats accessible to outsiders, according to the researcher. (Edward Berthelot/Getty)

Ways to stay safe when using AI apps

You do not need to stop using AI tools to protect yourself. A few informed choices can lower your risk while still letting you use these apps when they are helpful.

1) Be mindful of sensitive topics

AI chats can feel private, especially when you are stressed, curious or looking for answers. However, not all apps handle conversations securely. Before sharing deeply personal struggles, medical concerns, financial details or questions that could create legal risk if exposed, take time to understand how the app stores protects your data. If those protections are unclear, consider safer alternatives such as trusted professionals or services with stronger privacy controls.

2) Research the app before installing

Look beyond download counts and star ratings. Check who operates the app, how long it has been available, and whether its privacy policy clearly explains how user data is stored and protected.

3) Assume conversations may be stored

Even when an app claims privacy, many AI tools log conversations for troubleshooting or model improvement. Treat chats as potentially permanent records rather than temporary messages.

Advertisement

4) Limit account linking and sign-ins

Some AI apps allow you to sign in with Google, Apple, or an email account. While convenient, this can directly connect chat histories to your real identity. When possible, avoid linking AI tools to primary accounts used for work, banking or personal communication.

5) Review app permissions and data controls

AI apps may request access beyond what is required to function. Review permissions carefully and disable anything that is not essential. If the app offers options to delete chat history, limit data retention or turn off syncing, enable those settings.

6) Use a data removal service

Your digital footprint extends beyond AI apps. Anyone can find personal details about you with a simple Google search, including your phone number, home address, date of birth and Social Security number. Marketers buy this information to target ads. In more serious cases, scammers and identity thieves breach data brokers, leaving personal data exposed or circulating on the dark web. Using a data removal service helps reduce what can be linked back to you if a breach occurs.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Advertisement

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

Kurt’s key takeaways

AI chat apps are moving fast, but security is still lagging behind. This incident shows how a single configuration mistake can expose millions of deeply personal conversations. Until stronger protections become standard, you need to treat AI chats with caution and limit what you share. The convenience is real, but so is the risk.

Do you assume your AI chats are private, or has this story changed how much you are willing to share with these apps? Let us know your thoughts by writing to us at Cyberguy.com.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Advertisement

Copyright 2026 CyberGuy.com. All rights reserved.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

Backbone’s versatile pro controller is nearly matching its best price to date

Published

on

Backbone’s versatile pro controller is nearly matching its best price to date

Mobile gaming has come a long way over the course of the last decade or so, but we all know that smartphones simply can’t match the visceral, tactile feel you get while playing with a dedicated controller. Luckily, Backbone makes some excellent mobile options — including last year’s Backbone Pro, which is on sale at Amazon, Best Buy, and Target right now for $139.99 ($30 off), its second-best price to date.

In many ways, Backbone’s latest mobile controller is merely an updated take on what came before. The handheld device consists of two oblong halves with an extendable strip of plastic in the middle, allowing you to use it with Android devices and iPhone 15, 16, and 17 series phones. It plugs into your phone’s USB-C port and, once connected, you can game with two full-sized ALPs thumbsticks, a responsive D-pad, and A, B, X, and Y buttons. It also features two programmable back buttons, a 3.5mm headphone jack, better ergonomics than your phone, and averages up to 40 hours of battery life on a single charge.

The hardware is only part of the equation, though. Backbone’s intent with the Pro is for it to function as a more universal gamepad, and as such, the company’s software pulls together games from Apple Arcade, Netflix, Google Play, and other services into a singular app, allowing you to discover and launch games with little fuss. What’s more, you can use it to stream Xbox or PlayStation games — either from your console or the cloud —and connect it to a wealth of other devices via Bluetooth, including your PC, Steam Deck, and Apple devices like the iPad and Mac. Sure, the beefy controller looks a little awkward when you’re using it without a phone, but it’s a small price to pay for its added versatility.

Continue Reading

Technology

iPhone calendar spam invites are surging

Published

on

iPhone calendar spam invites are surging

NEWYou can now listen to Fox News articles!

You glance at your phone and see it. A calendar alert warns you that your iPhone is infected. Or that you won a prize. Or that your account will be locked. Your first thought might be panic. Your second step should be to pause.

Many Apple users are reporting a wave of fake calendar invites that appear out of nowhere. These alerts are not malware. However, they are a scam tactic. And they can quickly clutter your calendar with junk events and suspicious links. Let’s break down what is happening and how to fix it.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

How fake calendar invites get onto your iPhone

Here is the surprising part. Most of the time, no app is installed. Nothing comes through the App Store. You do not download anything obvious.

Advertisement

HOW TO STOP SPAM MAIL, POLITICAL TEXTS AND EMAIL SPAM FOR GOOD
 

Scammers are flooding Apple Calendar with spam subscriptions that trigger urgent alerts and phishing links. (Stanislav Kogiku/SOPA Images/LightRocket via Getty Images)

Instead, the problem often starts with a single tap. You might click a bad link in a message or on a website. That page can quietly prompt you to subscribe to a calendar. Once you tap approve, even by accident, the spam events begin to flow in.

Because it is a subscription, the alerts show up directly in your iOS notifications. Even if the related email lands in junk mail, the calendar event can still appear on your device. It feels invasive. But according to users discussing the issue on Reddit’s r/Apple forum, it usually does not mean your phone was hacked.

As one commenter put it, if scammers are using calendar events to reach you, they likely did not break into your device. They simply tricked you into subscribing. 

Advertisement

Why iPhone calendar spam alerts feel urgent and real

Scammers design these fake calendar invites to trigger panic fast. For example, one alert may claim your iPhone has a virus, while another promises a prize or warns that your account will be suspended. Instead of giving you time to think, the message pushes you to act immediately. As a result, many people tap before they pause.

However, that second click is where the real risk begins. In many cases, it redirects you to a phishing site that asks for passwords, credit card details or other personal information. Although the calendar alert itself is not malware, engaging with it can expose you to identity theft or financial fraud. In other words, the danger is not the notification. It is what happens next.

How to remove iPhone calendar spam invites

The good news is that removing the spam usually takes only a few steps.

Step 1: Check your subscribed calendars

  • Go to Settings
  • Scroll to the bottom and tap Apps
  • Click Calendar
  • Tap Calendar Accounts
  • Click Subscribed Calendars
  • Look for any subscription you do not recognize. Delete it.

That single action often stops the flood of alerts.

APPLE APP PASSWORD SCAM EMAIL WARNING
 

Fake iPhone calendar alerts may look like malware, but experts say they usually stem from unwanted subscriptions. (Jaap Arriens/NurPhoto via Getty Images)

Advertisement

Step 2: Remove the spam subscription inside the Calendar app

  • Open the Calendar app.
  • Tap the calendar icon at the bottom.
  • Find the suspicious subscription and tap the “i” next to it. Confirm it is junk and unsubscribe.

After you unsubscribe, you may still need to manually delete leftover events.

Step 3: Offload and reinstall the Calendar app

If the app continues to behave strangely, you can offload it.

Important note before you do this: Offloading the app removes the app itself but keeps your calendar data. Your events stored in iCloud, Google or other accounts remain intact. However, if you delete the app instead of offloading it, that can remove locally stored data. If your calendars are synced with iCloud or another account, your events will come back after reinstalling. Still, it is smart to confirm your calendars are syncing before making changes.

  • Go to Settings
  • Click General
  • Tap iPhone Storage
  • Click Calendar
  • Tap Offload App
  • Restart your phone
  • Then go back to Settings > General > iPhone Storage > Calendar and tap Reinstall App. You can also tap the Calendar icon on your Home Screen. If it shows a small cloud download symbol, tap it to reinstall.

Several users reported that this solved lingering issues.

FBI WARNS SENIORS ABOUT BILLION-DOLLAR SCAM DRAINING RETIREMENT FUNDS, EXPERT SAYS AI DRIVING IT
 

Apple users can stop calendar spam by deleting suspicious subscriptions in Settings and the Calendar app. (Gabby Jones/Bloomberg via Getty Images)

How to prevent calendar spam in the future

Advertisement

Now that your calendar is clean, the next step is prevention.

Here are smart habits that make a real difference:

  • Keep iOS updated so security patches stay current
  • Avoid tapping links in unexpected texts or pop-ups
  • Use strong antivirus software to block malicious websites and phishing links before they load. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
  • Never engage with alerts about prizes or infections
  • Consider a data removal service to limit how much of your personal information is exposed online. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com
  • Review and remove unknown calendar subscriptions regularly

Why Apple users are frustrated

Many users point out that even when a spam invite lands in junk mail, the event can still appear on the calendar. That disconnect feels like a flaw in the system. Some argue Apple should tighten how calendar subscriptions work. Still, personal awareness goes a long way. Scammers rely on quick reactions. Slow down, verify and stay skeptical of urgency.

Kurt’s key takeaways

Fake iPhone calendar spam invites are annoying. They are disruptive. And they can feel alarming. However, in most cases, they are the result of a sneaky subscription, not a hacked phone. A few careful taps can remove them. A few smarter habits can keep them from returning.

The next time your phone flashes an urgent warning, will you react instantly or take a breath and investigate first? Let us know by writing to us at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Advertisement

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Copyright 2026 CyberGuy.com. All rights reserved.

Advertisement
Continue Reading

Technology

Google Chrome is coming to Arm-powered Linux devices later this year

Published

on

Google Chrome is coming to Arm-powered Linux devices later this year

Why Arm + Linux now? In a blog post, Google only says that it “addresses the growing demand for a browsing experience that combines the benefits of the open-source Chromium project with the Google ecosystem of apps and features.” What we’re left wondering is whether Google’s talking about existing demand, or demand yet to come.

There’s certainly a growing demand for Linux. Some Verge editors have begun to ditch Windows with varying degrees of success. But those are our x86 desktops — there isn’t a lot of consumer-facing Linux on Arm chips, unless you count all the Linux-based Android phones out there. You can buy Linux on laptops from Dell, Lenovo, Framework, and such, but again, they use x86 chips. (And if you’re not a consumer, there’s already Chromium.)

But three of the companies that actually build Arm processors — Qualcomm, Nvidia, and Mediatek — may look to Linux as they try to compete with the Windows/Intel/AMD incumbents. Qualcomm told me in January that it sees “a lot of interest on other operating systems” beyond Windows for its PC-grade Arm chips. Nvidia could reveal its N1 and N1X processors for Arm laptops as soon as next week at its GTC 2026 developer conference.

While those Nvidia laptops might get announced with Windows, it wouldn’t be surprising if they targeted Linux too, once the basics like Chrome are sorted out. Google’s blog post specifically namedrops Nvidia’s DGX Spark as a target for Chrome — those $4,000+ beefy micro AI desktops, sold by a wide array of the company’s partners, also run Linux on Arm. Google says it’s putting Chrome into Nvidia’s package manager to make installation easier; everyone else will have to go to chrome.com/download when the browser arrives in Q2.

Continue Reading

Trending