Cybersecurity researcher Jeremiah Fowler identified unsecured databases tied to Sears Home Services containing 3.7 million AI chatbot transcripts, audio call recordings, and text transcriptions. The records covered the period from 2024 through 2026 and were accessible without authentication.
The exposed material included personally identifiable information belonging to customers. Names, physical addresses, and email addresses appeared throughout the set, with phone numbers present in a portion of the records. Individual entries also carried details on products purchased, account identifiers, service history, repair records, and scheduled delivery appointments.
The transcripts appeared in English and Spanish and referenced two internal system names, Samantha and KAIros, indicating that the logs were generated by automated customer service agents handling both chat and voice channels.
The incident follows a pattern seen across several AI deployments during the same period. In January 2026, a security researcher found an exposed database belonging to Chat and Ask AI, an application claiming more than 50 million users, traced to a Firebase misconfiguration. That exposure covered hundreds of millions of private user messages and extended to other applications published by the same developer, Codeway, which patched the issue across its portfolio within hours of disclosure.
In May 2026, a United States bank disclosed a security lapse after sharing customer data with an AI application.
Source: Cybernews - https://cybernews.com/ai-news/ai-chatbot-data-leak-sears/
