A review of AI application security incidents counted at least 20 documented breaches between January 2025 and February 2026, exposing the personal data of tens of millions of users. The striking finding is how uniform the causes were across otherwise unrelated products.

Researchers attribute nearly every incident to a short list of preventable configuration errors: misconfigured Firebase databases, missing Supabase row-level security, hardcoded API keys, and exposed cloud backends. These are deployment mistakes rather than sophisticated attacks, and each leaves a database reachable without authentication.

The scale of individual events was large. The Chat and Ask AI leak alone exposed roughly 406 million records, including more than 300 million chat messages from an estimated 18 to 25 million users. An earlier exposure tied to an AI chatbot vendor revealed survey data from Canva Creators program participants, including email addresses and detailed responses.

The recurrence of identical root causes across many products points to a systemic issue in how quickly AI applications are shipped relative to the security review they receive. Analysts tracking the incidents note that standard cloud security practices would have prevented most of them.

Source: Barrack AI - https://blog.barrack.ai/every-ai-app-data-breach-2025-2026/