Risk level: high. Can you change it: no. Found in 5 breaches in this directory.
What this data is
The text of conversations you had in an app or website chat, including direct messages, group chats and support chats, sometimes with attached files, images and voice notes.
The risk on its own
Private messages are written for one audience, so they hold what people would never post: relationship details, intimate photos, arguments, money trouble, gossip about colleagues and sometimes passwords or codes sent to a friend. Even without your account name, chats usually identify you through names, places and in-jokes. The damage is personal and reputational first, then financial.
The risk combined with other data
Tied to your real name and email it becomes leverage. Extortionists quote your own words back to you, and impersonators learn exactly how you write to the people close to you. Anything you shared in a chat, such as an address, a bank account number or a login, is exposed along with it.
How criminals use it
A sextortion message threatens to send intimate images or messages from the chat to your family and employer unless you pay.
Someone copies your writing style and nicknames to message your friends and ask for money.
Passwords, one-time codes or bank details you sent in a chat are used directly.
Screenshots of private conversations are posted to embarrass you or damage relationships at work.
What to do now
Search your own history in the breached app for passwords, card numbers, ID photos and addresses, and change or cancel anything you find.
If intimate images were involved, use StopNCII.org to block them on participating platforms, or Take It Down from NCMEC if you were under 18 in the images.
Do not pay an extortionist. Stop replying, keep screenshots and report it to police and to the platform.
Change the password on the chat service, turn on two-factor authentication and sign out of all other sessions.
Warn close contacts that messages imitating you may arrive, and agree a way to confirm any money request.
Delete old conversations or the whole account, and ask the company to confirm the deletion in writing.
Frequently asked questions
Someone is threatening to publish my chats. What do I do?
Do not pay and do not negotiate, because paying usually brings more demands. Keep evidence, block the sender, and report it to police and the platform.
Weren't my messages end-to-end encrypted?
If the service used end-to-end encryption properly, it could not read message content, so a server breach would expose little. Many chat services do not work that way, so check the breach notice.
Can I get leaked chats taken down?
You can report posts to the platforms hosting them, and privacy regulators can help where laws apply. Copies traded privately cannot be recalled, so deal with the passwords and details inside them first.
Breaches that exposed this data
ZAP-Hosting: 2021-11-22, 747K accounts, Browser user agent details, Chat logs, Email addresses, IP addresses, Names, Phone numbers
The Real World: 2024-11-15, 324K accounts, Chat logs, Email addresses, Usernames
Technic: 2018-11-30, 265K accounts, Chat logs, Email addresses, IP addresses, Passwords, Private messages, Time zones
Muslim Match: 2016-06-24, 150K accounts, Chat logs, Email addresses, Geographic locations, IP addresses, Passwords, Private messages
Toy Battles: 2026-02-06, 1.0K accounts, Chat logs, Email addresses, IP addresses, Usernames
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.