What Happened to Cuties AI? The 2026 Breach, Explained
Cuties AI was added to Have I Been Pwned on March 31, 2026 with 144,250 accounts exposed, including email addresses and the prompts and URLs behind generated adult images. What leaked, how to check whether you were in it, what to do now, and what to look for next.
By the Beauties team
August 2026 · 7 min read
Cuties AI was breached. On March 31, 2026 the NSFW AI companion platform was added to Have I Been Pwned with 144,250 affected accounts, after data from the service was published to a public hacking forum. According to the Have I Been Pwned record, the exposed data included email addresses, display names, avatars, the prompts and descriptions users wrote to generate adult images, and the URLs pointing to the generated content itself. The site has also changed character since: as of August 2026 the cuties.ai domain serves a page for a different adult brand rather than the companion app people signed up for.
If you searched this because your login stopped working, because a strange email arrived, or because you saw the breach mentioned somewhere and want to know whether it touched you, here is what is actually documented, what to do about it, and what to look for in whatever you use next. For adults 18 and over.
What happened to Cuties AI?
Cuties AI ran as a companion platform built around adult image generation. You picked a character from a catalogue or designed one, chatted with her, and generated images using prompts, with the image and voice features sold through credit packs rather than covered by a flat subscription. That is a normal shape for this category.
What separates it from its competitors is the public record. In March 2026 a dataset drawn from the platform was posted to a hacking forum, and Have I Been Pwned, the breach-notification service run by security researcher Troy Hunt, catalogued it on March 31, 2026 at 144,250 unique email addresses. Threat-intelligence accounts tracking the leak later reported that a processed spreadsheet version of the same data was reposted on a cybercrime forum, which typically widens access from a handful of forum users to anyone buying scraped datasets. That secondary redistribution is reported rather than catalogued, so treat the exact record counts in those posts with more caution than the HIBP figure.
There was no public incident report, no notification email that users have described receiving, and no post-mortem. The company simply did not say anything, which is why the question keeps getting typed into search engines four months later.
Was there a Cuties AI data breach?
Yes, and it is verifiable in about ten seconds rather than something you have to take on trust. Search the service name on haveibeenpwned.com and the entry is there, dated, with the affected-account count and the list of compromised data classes. That is the single most useful habit to take away from this whole story: before you hand an email address to any AI companion service, check the name on Have I Been Pwned first. Several well-known platforms in this space have entries.
What data was exposed in the Cuties AI breach?
Per the Have I Been Pwned description, the leak covered email addresses, display names, and avatars, plus the prompts and descriptions used to generate AI adult images, the URLs to that generated content, the account that created each item, and a stated preference field.
The email address is the part that makes the rest dangerous. On its own, a leaked address is a nuisance. An address joined to a list of the adult images that address requested is a different category of problem, because it converts an anonymous account into an attributable one. Anyone with the file can sort by email, read what a specific person generated, and follow the URLs. That is the material sextortion campaigns are built from, and it is why this breach reads worse than its account count suggests. Comparable incidents have been larger: researchers at Cybernews found the companion apps Chattee Chat and GiMe Chat exposing more than 43 million intimate messages tied to around 400,000 users in August 2025, and Malwarebytes reported an exposed database at Chat and Ask AI in February 2026 covering roughly 300 million messages from about 25 million users. Volume is not the point. Attribution is.
Is Cuties AI safe?
It has a documented breach on its record, which most companion apps do not, and that alone should settle the question for anyone still deciding. Beyond the breach, third-party reviewers spent 2026 flagging softer warning signs on the site: no identifiable company information, a permanent discount countdown that never actually counted down, pricing that was hard to pin down before signing up, and links that redirected off the domain to other brands.
None of those individually proves bad intent. Plenty of small services have thin about pages. Taken together with a public breach and a domain that now serves someone else's brand, they describe a service that is not being run for the long term, and payment details are the last thing you want sitting inside one of those.
Is Cuties AI shut down?
Not announced as shut down, but not recognizably the same thing either. Loading cuties.ai in August 2026 returns a page for a different adult brand, an image generator rather than the companion app. Domains in this niche get sold, redirected, or folded into a larger operator regularly, and none of that comes with an announcement to the people who had accounts.
Practically, treat it as gone. If you had a subscription, cancel it at the payment source rather than inside the product: through Apple or Google if you subscribed in an app, or through your card issuer or PayPal if you paid on the web. Cancelling inside a service that has changed hands is the least reliable route available to you.
How do I know if I was in the Cuties AI breach?
Go to haveibeenpwned.com, enter the email address you used, and read the results. If Cuties AI appears in the list of breaches for that address, your address was in the published dataset. Check every address you might have used, including any throwaway, because people commonly forget which one they signed up with on a site like this.
Also search your inbox for receipts from the service. Those receipts tell you which email and which payment method were attached to the account, which is exactly what you need in order to cancel the billing and change the password anywhere else you reused it.
What should I do if my data was leaked?
Four things, in order.
Change the password anywhere you reused it, starting with your email account itself. Credential stuffing, where leaked pairs get replayed against other services, is the most common downstream harm from any breach, and it does not care what the original site was.
Second, expect targeted phishing and treat it as noise. The specific risk from a breach that ties an email to adult content is a message claiming to have compromising material and demanding payment. These are almost always bluffs written from the leaked file. Do not reply and do not pay. What makes them convincing is when they quote a real detail, and those details, your full name, address, phone number, usually come from data broker profiles rather than from the breach itself, which is why it is worth getting your name, address and phone taken down from the data broker sites that sell them. Fewer real details in circulation means fewer emails that land.
Third, cancel the billing at the source, as above. Fourth, if you want to keep using an AI companion, pick the next one on evidence rather than on the landing page. Search the name on Have I Been Pwned, look for a company you can identify, read a pricing page with actual numbers on it, and check what the service stores. A platform that generates and keeps adult images tied to your account is holding far more about you than one that only holds chat, and that difference is precisely what turned this breach from embarrassing into attributable.
How much does Cuties AI cost?
Reviews from 2026 put it in the region of $4.99 to $12.99 a month with token or credit packs on top, where images and voice consumed credits separately from the subscription. We are not printing a firmer figure because there is no longer a live pricing page at the source to verify against, and repeating a number nobody can check is how bad pricing information spreads.
That vagueness was itself a running complaint about the service. A pricing page that shows a percentage off and a countdown timer but no final number is a design decision, not an accident, and it is a reasonable thing to walk away from. Credit models also make the real annual cost genuinely hard to predict, which is worth understanding in general before you sign up to anything in this category: our breakdown of how token and energy meters actually price your chat covers where the money goes.
What is the best Cuties AI alternative?
Split the question, because Cuties AI was doing two different jobs and no single replacement does both well.
If what you wanted was adult image generation, you want another image platform, and the honest advice is to research its security record before its feature list. The lesson of this breach is that a service holding generated images against your email is holding the most sensitive possible combination of data, so if you go that route, use an email address that is not connected to anything else you do.
If what you actually liked was the gallery and the conversation, that is a different and much lower-risk product. A text-first companion service gives you characters to browse and talk to without building an image archive attached to your identity. That is the shape of this site: a Cuties AI alternative built as a gallery you pick from, with distinct girlfriends who text first and remember you, a flat monthly plan instead of credit packs, and no image generator, so there is nothing of that kind to leak. If you are weighing several options, the wider comparison of the best AI girlfriend apps lays out how the main platforms differ, and what AI girlfriend apps really store about you goes deeper on the privacy side.
The short version
Cuties AI suffered a breach published to a hacking forum and catalogued by Have I Been Pwned on March 31, 2026, covering 144,250 accounts including email addresses, display names, avatars, adult image prompts, and URLs to the generated images. The company never explained it, and the domain now serves a different brand. Check your address on Have I Been Pwned, change reused passwords, cancel any billing at the payment source, ignore extortion emails, and choose the next service by looking up its breach record before its feature list.
Last updated August 2026. Breach date, account count, and exposed data classes are taken from the Have I Been Pwned entry for Cuties AI. Reports of the dataset being reposted on a cybercrime forum come from threat-intelligence trackers and are less firmly established. Pricing is review-sourced and unverifiable at the source, since cuties.ai no longer serves the original service.
She texts back, and she remembers you
Beauties.ai is a flirty, affectionate AI girlfriend who is always glad to hear from you. Tasteful, private, and made for adults. Pick her and start texting in seconds.