Unsecured database of keyboard app AI.type leaks 577GB of data from 31M users and all of their contacts, includes 374M+ phone numbers, 10M+ email accounts, more
some 374.6 million phone numbers alone. http://zd.net/2A7bkFu pic.twitter.com/AinjASnOyG
Context & Ripple Effects
The AI.type leak is an early entry in a pattern this coverage keeps confirming: consumer apps that harvest far more data than their function requires, then store it in databases left open to the internet. A keyboard app has no obvious need for users' full contact books, yet the 577GB trove includes roughly 374.6M phone numbers and 10M+ email accounts — most belonging to people who never installed anything.
Later findings in the same arc show the pattern is structural, not one-off: Dalil's caller ID app exposed GPS coordinates for weeks, JusTalk left millions of plaintext conversations and call logs open since January 2022, and an unsecured database tied 419M+ phone numbers to Facebook accounts. Each case involves an app or platform whose core value depends on ingesting other people's personal data.
First-order effects
- 31M AI.type users have their device contents exposed, but the bigger blast radius is their contacts — hundreds of millions of phone numbers and email addresses now usable for spam, phishing, and SIM-swap reconnaissance against people who never agreed to the app's terms.
- AI.type faces immediate trust and distribution damage on Google Play, where keyboard apps live or die by install volume.
Second-order effects
- App-store reviewers and Android users get fresh evidence for scrutinizing permission requests from utility apps, pressuring every keyboard and caller-ID developer to justify contact access or lose installs.
- Security researchers are incentivized to keep scanning public cloud storage for these troves — as they did with Dalil, JusTalk, and the Facebook-linked database — turning routine misconfigurations into headline disclosures.
Third-order effects
- If the pattern holds, the durable problem is secondary data: apps holding contact books and call logs of non-consenting third parties, which GDPR-era rules (arriving months after this leak) treat as a compliance liability, not just a security lapse.
- Repeated researcher discoveries of open databases push the industry toward defaults — encrypted storage, restricted buckets, breach-notification obligations — where 'misconfigured server' stops being a viable excuse.
The trend: Consumer apps that monetize harvested social graphs keep leaking them through unsecured cloud databases, making third-party contact data the recurring casualty of mobile's data-hungry business model.