Data breach
ai.type
- Records
- 72,674,006
- Breach date
- 5 December 2017Estimated
- Added
- 1 December 2024
What was exposed
5 types of data · 2 more reported
- Contact lists72,674,006
- Phone models72,671,264
- Phone brands72,662,829
- Email addresses71,411,860
- IP addresses33,920,836
- NamesReported, not counted
- Phone numbersReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In December 2017, an unprotected database belonging to ai.type, an Israel-based developer of a popular custom keyboard app for Android and iOS, left the personal records of more than 31 million app users exposed to anyone with an internet connection. Security researchers at Kromtech Security Center, including Bob Diachenko, found a 577-gigabyte MongoDB server that required no password to open. According to our investigation team, the exposure is now associated with a dataset of roughly 72.7 million records, and the estimated attack date is December 5, 2017. No hacking group has claimed responsibility, which is consistent with an unsecured server rather than an intrusion. Ai.type's founder acknowledged the exposure and said the database was secured after researchers reported it, though the researchers said it took several attempts to reach the company.
December 5, 2017: Kromtech Security Center discloses an unsecured MongoDB database containing 577 GB of ai.type user data, covering more than 31 million users; reports appear the same day in The Register and later ZDNet.
December 7, 2017: ESET's WeLiveSecurity and other outlets report further details, including a table with over 8.6 million entries of typed text, some containing email addresses paired with passwords.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses, present in about 71.4 million records
IP addresses, present in about 33.9 million records
Phone brand, present in about 72.7 million records
Phone model, present in about 72.7 million records
Contact lists, present in about 72.7 million records
The Kromtech researchers and subsequent reporting by The Register, ZDNet, and ESET described additional material in the exposed database, including users' names, location data, device identifiers such as IMSI and IMEI numbers, Android version details, links to public Google profiles and social media accounts, and lists of installed apps, including banking and dating apps. One table held 374.6 million phone numbers collected from users' address books, and another held more than 8.6 million entries of typed text, in some cases including email addresses alongside passwords. The company's founder disputed some of these details, saying the server held a secondary, mostly statistical database and that no passwords or payment information were collected or stored.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The contact-list exposure matters beyond the affected users themselves: people who never installed ai.type could still have had their names and phone numbers uploaded by a contact who did. Exposed email addresses and phone numbers are useful for phishing and smishing, and the reported keystroke logs, which allegedly contained credentials typed on the keyboard, could give criminals direct access to online accounts if the text was authentic and complete. Location data, device identifiers, and lists of installed apps, particularly banking apps, also enable more convincing targeted scams. Anyone who typed passwords while using the free version of the app should treat those credentials as potentially compromised.
What Is ai.type Doing in Response?
Ai.type founder and chief executive Eitan Fitusi told the BBC and The Register that the database was secured after Kromtech reported the issue, and said the exposed server was a secondary database holding largely statistical information. He said the company does not collect or store passwords or credit card details and that he was confident in the company's security. Diachenko disputed the characterization, noting the breadth of personal information present. We found no record of a formal user notification from the company as of September 25, 2026.
What Should You Do If You Were Affected?
If you used the ai.type keyboard app around 2017, especially the free version, take these steps:
Change passwords for any accounts you accessed while the app was installed, starting with email and financial accounts.
Do not reuse the old password anywhere else.
Watch for phishing emails or text messages that reference your contacts, location, or installed apps, since that specificity can make scams more convincing.
Warn contacts whose numbers may have been uploaded if you believe your address book was affected.
Review which third-party keyboards have access to your device and consider removing ones you no longer use.
In the news
- BBC News: Millions caught in virtual keyboard app data breachbbc.com (opens in a new tab)
- The Register: Data-slurping keyboard app makes Mongo mistake with user datatheregister.com (opens in a new tab)
- WeLiveSecurity (ESET): Virtual keyboard app exposes personal data of 31 million userswelivesecurity.com (opens in a new tab)
- Comms Risk: Android Keyboard App Leaks Data of 31mn Userscommsrisk.com (opens in a new tab)
