/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Unsecured database of keyboard app AI.type leaks 577GB of data from 31M users and all of their contacts, includes 374M+ phone numbers, 10M+ email accounts, more

some 374.6 million phone numbers alone. http://zd.net/2A7bkFu pic.twitter.com/AinjASnOyG

ZDNet Zack Whittaker

Context & Ripple Effects

The AI.type leak is an early entry in a pattern this coverage keeps confirming: consumer apps that harvest far more data than their function requires, then store it in databases left open to the internet. A keyboard app has no obvious need for users' full contact books, yet the 577GB trove includes roughly 374.6M phone numbers and 10M+ email accounts — most belonging to people who never installed anything.

Later findings in the same arc show the pattern is structural, not one-off: Dalil's caller ID app exposed GPS coordinates for weeks, JusTalk left millions of plaintext conversations and call logs open since January 2022, and an unsecured database tied 419M+ phone numbers to Facebook accounts. Each case involves an app or platform whose core value depends on ingesting other people's personal data.

First-order effects

  • 31M AI.type users have their device contents exposed, but the bigger blast radius is their contacts — hundreds of millions of phone numbers and email addresses now usable for spam, phishing, and SIM-swap reconnaissance against people who never agreed to the app's terms.
  • AI.type faces immediate trust and distribution damage on Google Play, where keyboard apps live or die by install volume.

Second-order effects

  • App-store reviewers and Android users get fresh evidence for scrutinizing permission requests from utility apps, pressuring every keyboard and caller-ID developer to justify contact access or lose installs.
  • Security researchers are incentivized to keep scanning public cloud storage for these troves — as they did with Dalil, JusTalk, and the Facebook-linked database — turning routine misconfigurations into headline disclosures.

Third-order effects

  • If the pattern holds, the durable problem is secondary data: apps holding contact books and call logs of non-consenting third parties, which GDPR-era rules (arriving months after this leak) treat as a compliance liability, not just a security lapse.
  • Repeated researcher discoveries of open databases push the industry toward defaults — encrypted storage, restricted buckets, breach-notification obligations — where 'misconfigured server' stops being a viable excuse.

The trend: Consumer apps that monetize harvested social graphs keep leaking them through unsecured cloud databases, making third-party contact data the recurring casualty of mobile's data-hungry business model.