An exposed database tied to Sears Home Services left roughly 3.7 million customer records accessible without authentication, including chat transcripts, audio recordings and text transcriptions of customer interactions dating from 2024 to 2026.

The exposed files referenced two internal AI systems by name. One, identified as "Samantha," is a customer facing chatbot. The other, identified as "KAIros," is described as a broader AI platform used for scheduling and operational support.

Call recordings and chat transcripts from a home services operation typically contain a specific combination of information: customer names, service addresses, phone numbers, appliance and system details, appointment times and, in some interactions, payment discussion. Audio recordings carry the additional exposure of voice data.

The incident sits within a pattern of AI adjacent data exposures documented through 2026. A separate leak affecting the Chat and Ask AI application, which has more than 50 million downloads across the Google Play and Apple app stores, exposed approximately 300 million messages tied to 25 million users through an unsecured database, according to the security researcher who identified it.

Another case involved a McDonald's hiring chatbot, where researchers reported that more than 64 million job applicants had personal information exposed after the system was accessed using the password 123456.

In March, security researchers demonstrated that an autonomous AI agent obtained read and write access to McKinsey's internal generative AI platform, Lilli, within two hours, reaching millions of internal messages and file records.

Source: Cybernews - https://cybernews.com/ai-news/ai-chatbot-data-leak-sears/