ai.type data breach

Breach date: 2017-12-05. Added to this index: 2017-12-08. Accounts affected: about 21M. Domain: aitype.com.

What happened

In December 2017, the virtual keyboard application ai.type was found to have left a huge amount of data publicly facing in an unsecured MongoDB instance. Discovered by researchers at The Kromtech Security Center, the 577GB data set included extensive personal information including over 20 million unique email addresses, social media profiles and address book contacts. The email addresses alone were provided to HIBP to enable impacted users to assess their exposure.

Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.

What was exposed

  • Address book contacts: The contacts you allowed an app to upload from your phone, typically names, phone numbers, email addresses and sometimes relationship labels such as Mum or Boss.
  • Apps installed on devices: An inventory of the applications present on your phone or computer, collected by an app, an advertising kit or a device management tool. It usually includes package names and sometimes versions.
  • Cellular network names: The name of your mobile phone company, such as Telstra, Vodafone, T-Mobile or EE, recorded by an app at signup or read from the phone itself.
  • Dates of birth: Your full birth date, day, month and year, collected at signup for age checks, identity verification, insurance quotes, birthday offers or government services.
  • Device information: Technical details an app or website recorded about your device: make and model, operating system version, screen size, language, carrier, and sometimes the device name or advertising ID.
  • Email addresses: The email address you used to register or log in. It is the most common field in breaches because it doubles as your username on most sites.
  • Genders: The gender or sex recorded on your profile, usually picked from a list at signup, sometimes with a title such as Mr or Ms or a gender identity option beyond male and female.
  • Geographic locations: A general location recorded on your account, such as a country, state, city, postcode or region, either typed in by you or estimated from your IP address.
  • IMEI numbers: The International Mobile Equipment Identity, a unique number that identifies your phone handset on mobile networks. You can see yours by dialling *#06#.
  • IMSI numbers: The International Mobile Subscriber Identity, a unique number stored on your SIM or eSIM that identifies your subscription to the mobile network. It is different from your phone number and from the handset's IMEI.
  • IP addresses: The network addresses your devices used when you signed up, logged in or posted, recorded by almost every website in its access logs.
  • Names: Your first name, surname and sometimes middle name or initials, as you gave them when you signed up. It appears in almost every breach because nearly every account asks for it.

What to do now

  1. Check whether your own address is in this dataset with the free email breach check.
  2. Review the accounts connected to this service and turn on two-factor authentication.
  3. Turn on two-factor authentication on your email account first, because it is the reset path for everything else.
  4. Treat calls and messages that quote real details about you as hostile until you verify them another way.

Frequently asked questions

What data was leaked in the ai.type breach?

The ai.type breach exposed Address book contacts, Apps installed on devices, Cellular network names, Dates of birth, Device information, Email addresses, Genders, Geographic locations, IMEI numbers, IMSI numbers, IP addresses, Names, Phone numbers, Profile photos, Social media profiles. About 21M accounts were affected.

Was I affected by the ai.type breach?

Run the free email breach check with the address you used on that service. It will tell you whether your address appears in this dataset.

What should I do about the ai.type breach?

Treat any message that quotes details from this breach as suspicious, turn on two-factor authentication, and consider removing your details from people-search sites if your address or phone was included.

Next steps