An unsecured database tied to Sears Home Services exposed approximately 3.7 million records generated by the company's artificial intelligence customer service systems, according to security researchers who identified the storage. The appliance repair provider operates across the United States, and the exposed material covered interactions dating from 2024 through 2026.

The records included chat transcripts, audio recordings of customer calls, and text transcriptions of those recordings. File references within the storage identified two systems by name. One, labeled Samantha, functioned as a customer-facing chatbot. The second, identified as KAIros, operated as a broader platform handling scheduling and operational support functions.

The incident falls into a pattern of exposures involving AI-adjacent infrastructure rather than the models themselves. Chat logs, transcription output, and conversational audio accumulate in storage layers that sit outside the security review applied to primary customer databases, and access controls on those stores have repeatedly proven weaker.

Comparable incidents have surfaced through 2026. More than 64 million applicants to McDonald's had personal information exposed through a configuration weakness in a hiring chatbot. Chat and Ask AI, an application claiming more than 50 million users across the Google Play and Apple app stores, left roughly 300 million messages from over 25 million users reachable through an exposed database. Thousands of Instagram accounts were taken over in early 2026 when attackers used Meta's AI chatbot to trigger password resets.

Companies deploying conversational systems retain records that carry the same regulatory obligations as any other customer data.

Source: Cybernews - https://cybernews.com/ai-news/ai-chatbot-data-leak-sears/