MARCH 21, 2026
In February 2026, Brandefense threat analysts identified a high-severity post on an underground forum in which an unidentified threat actor claimed to have exfiltrated the complete database of a popular AI-powered application. The actor alleged that the breach affected more than 1,000,000 registered users and offered the full dataset for free download, with a credit requirement attached — a distribution model commonly used to build reputation within threat actor communities.
The leaked data, examined by our team, includes Google OAuth tokens, active session tokens, user-generated content, personal identifiers, subscription records, and account credentials. The exposure of OAuth tokens in particular presents a severe escalation risk, as these tokens can be used to access third-party services linked to the compromised accounts — extending the blast radius far beyond the breached platform itself.
| ⚠ CRITICAL: Active Google OAuth and session tokens were found in the dataset. If valid, these tokens allow attackers to authenticate as victims without needing a password. |
Our analysts reviewed a sample of the alleged dataset. The breach appears to encompass multiple database tables exported in JSON format — a structure consistent with a direct database dump rather than a scraping or API abuse incident. Below is a breakdown of each exposed data category:
| Data Category | Fields Exposed | Risk Level |
| Account / OAuth Records | Google OAuth tokens, refresh tokens, access tokens, provider account IDs, token expiry timestamps | CRITICAL |
| Session Records | Session tokens, user IDs, expiry timestamps | CRITICAL |
| User Records | Full name, email address, username, profile picture URL (Google CDN), credit balance, invite codes, creation date, user unique IDs | HIGH |
| Subscription Records | Stripe customer IDs, subscription IDs, plan names, plan codes, credit allocations, expiry dates, billing source | HIGH |
| Verification Tokens | Email verification tokens, associated email addresses, expiry timestamps | HIGH |
| Messages / Content Records | User-generated content IDs, content type, host content references, aggregate IDs, creation timestamps | MEDIUM |
| User Badges | Badge assignments, user identifiers | MEDIUM |
| User Blocks / Shares | Block relationships, shared content records | LOW |
| Push Tokens | Device push notification tokens, user linkage | MEDIUM |

While the root cause has not been officially confirmed, the structure and completeness of the leaked dataset provides meaningful forensic clues. Based on our analysis:
The exported files follow a consistent, relational database structure. Each table is exported as a standalone JSON array — a pattern that aligns with direct database access via an ORM (Object Relational Mapper) export, a compromised backup file, or unauthorized administrative access. The breadth of coverage across all major tables rules out a targeted API abuse scenario.
The Account.json file contains what appear to be live Google OAuth access tokens and refresh tokens. OAuth tokens are temporary credentials that allow applications to act on behalf of a user. A refresh token, if not revoked, can be used indefinitely to generate new access tokens — meaning attackers may retain persistent access to linked Google accounts even after the compromised platform rotates its own credentials.
⚠ IMPORTANT: Refresh tokens do not expire unless explicitly revoked by the user or Google. Any user who authenticated via Google OAuth on this platform should immediately revoke third-party access at myaccount.google.com/permissions.
Session.json contains active session tokens with future expiry timestamps (some extending to early 2026). Active session tokens can be used directly to hijack authenticated sessions without requiring any credentials — a technique known as session hijacking or cookie theft.
The Subscriptions.json file exposes Stripe customer IDs. While Stripe customer IDs alone do not grant access to payment card data, they can be used in combination with a compromised Stripe secret key to retrieve billing information or manipulate subscription states. Organizations using Stripe should rotate API keys immediately if this data is confirmed.

The alleged compromise represents a significant reputational and regulatory risk for the affected platform. Under GDPR, CCPA, and other applicable data protection frameworks, the exposure of personal data — including email addresses, profile pictures, and unique identifiers — triggers mandatory breach notification obligations. Failure to comply with notification timelines can result in substantial regulatory fines.
The exposure of user-generated content, including AI prompts and generated media, raises additional privacy concerns. These records may reveal sensitive personal interests, business use cases, or private creative work, each carrying its own reputational risk for users if publicly disclosed.
| Attack Vector | Likelihood | Potential Impact |
| OAuth Token Abuse / Account Takeover | Critical | Immediate account compromise across linked services |
| Session Hijacking | High | Direct access to active authenticated sessions |
| Targeted Phishing Campaign | Critical | Elevated open & click rates due to PII richness |
| Credential Stuffing Against Other Platforms | High | Password reuse exploitation across unrelated services |
Areas they said they are still investigating include:
| If you have an account on the affected platform, take the following steps immediately: |
This breach was identified through Brandefense’s continuous dark web and underground forum monitoring infrastructure. Our platform maintains 24/7 automated surveillance across thousands of threat actor forums, leak sites, Telegram channels, and private marketplaces — enabling our analysts to surface high-severity incidents within hours of initial posting.
Upon detection, our Threat Intelligence team validated the claims by analyzing the provided sample data, cross-referencing the exposed fields against known database structures, and assessing the technical credibility of the actor’s claims.
| Detection Capability | Value Delivered |
| Underground Forum Monitoring | Breach post identified within hours of initial publication |
| Dark Web Data Validation | Sample analysis confirmed data authenticity and scope |
| Actor Profiling | Distribution model (free share + credit requirement) mapped to known reputation-building behavior |
| Impact Scoring | High-severity classification triggered based on OAuth token exposure and user volume |

Take control of your digital security with an exclusive demo of our powerful threat management platform.