Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology6 min read

ExpressVPN uncovers 3.7 million items of leaked AI chatbot data. A reminder of how vital encryption is | TechRadar

Leaked data points included voice and text messages, and even private audio recordings lasting up to 4 hours Discover insights about expressvpn uncovers 3.7 mil

TechnologyInnovationBest PracticesGuideTutorial
ExpressVPN uncovers 3.7 million items of leaked AI chatbot data. A reminder of how vital encryption is | TechRadar
Listen to Article
0:00
0:00
0:00

Express VPN uncovers 3.7 million items of leaked AI chatbot data. A reminder of how vital encryption is | Tech Radar

Overview

Express VPN uncovers 3.7 million items of leaked AI chatbot data. A reminder of how vital encryption is

Leaked data points included voice and text messages, and even private audio recordings lasting up to 4 hours

Details

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Express VPN uncovered massive amounts of AI chatbot leaked data

If you heard that up to 3.7 million pieces of private user data had been made public, you might well assume it was the report of a major hack. However, a recent investigation published by Express VPN proves just how easy it is to lose your privacy when basic security measures such as password protection and encryption aren’t in place.

Conducted by cybersecurity researcher Jeremiah Fowler, the report uncovered a case in which massive amounts of customer data were leaked from AI-powered chatbots used by retailers for customer service.

If you're on this page, chances are that the best VPNs are already protecting your digital privacy while you browse or stream content online, thanks to their top-notch encryption features.

Is your AI chat history public? These 198 i OS apps just leaked user data

'The best way to protect user data is not to collect it in the first place' - top VPN maker reveals Express AI, possibly the most secure and safe AI platform around right now

I’m a cybersecurity professional, here’s why I’m preparing for an AI data breach

But when a retailer or third-party service hasn’t taken adequate measures to protect your data, even the most tech-savvy users may not realize the enormous risks that they are subject to if leaked information falls into the wrong hands.

Fowler discovered three separate publicly accessible databases that were neither password-protected nor encrypted and contained 3.7 million records, including personal data such as email and home addresses, and phone numbers.

To give an example of the vastness of the data exposed, even an initial sampling included 1,422,577 audio recordings of customers. In terms of data, even at a glance, this included text transcripts totalling 3.9TB, 207,381 Excel files, and audio recordings totaling 415.2GB.

The limited sample contained transcripts and audio files belonging to Sears Home Services, a US retail and repair business that has embraced AI chatbots in English and Spanish for the purposes of automating their scheduling, phone calls, and online chats.

The files contained 54,359 complete transcripts of the conversations customers had with AI chatbots and their corresponding audio recordings.

Fowler pointed out that the system also continued to record audio files if the customer had not hung up properly, meaning that the audio files contained up to four hours of background conversation and vast amounts of biometric voice data.

The expert provided an overview of the data presented, sharing screenshots of filesystem structures and the types of files they contained. These illustrated how the data could be accessed, including how audio files could be played in any web browser and the convenient user interfaces provided for interacting with the filesystem.

Safer Internet Day – How the VPN industry is reacting to the rising risks of AI

Shock report claims Android apps have leaked over 730TB of user data and Google secrets - here are some of the worst offenders around

Most Brits worry about online privacy, but they trust the wrong apps

While Fowler stated that public access to the data was immediately restricted after he sent a responsible disclosure notification to Sears Home Services' parent company, Transformco, he remained concerned.

The investigation highlighted that with AI-driven automation being capable of storing massive amounts of highly sensitive data, there is a significant risk that some companies will act irresponsibly and leave user data exposed — a bleak scenario when estimates say that deepfake‑enabled fraud losses are forecast to reach US $40 billion by 2027.

This vast amount of data could enable hackers to link identities or replicate users’ digital profiles for criminal purposes; in such cases, virtual private network (VPN) tools prove useless if the weak link is the very company to which you have voluntarily entrusted your data via chatbots or other apps.

Express VPN urges users to remain vigilant and offers practical advice, including using strong passwords and taking extra precautions in sensitive situations.

Also, be cautious when receiving unsolicited emails, text messages, or phone calls that reference information you may have previously shared with a company or service.

And with the rise in voice cloning scams, agree on a password with family and friends to use in the unlikely event that you receive a call from them asking for money or help.

Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

Silvia Iacovcich is a tech journalist with over five years of experience in the field, including AI, cybersecurity, and fintech. She has written for various publications focusing on the evolving regulatory landscape of AI, digital behavior, web 3, and blockchain, as well as social media privacy and security regulations.

You must confirm your public display name before commenting

1I asked Chat GPT what to watch across 6 streaming apps — and it nailed it

2 The Madison cast say this Robert Redford film is unmissable — stream it here

3I found 6 unmissable 3D printer deals based on our tests, starting from $199 in the Spring Sales

4 Over 29 million secrets were leaked on Git Hub in 2025, and AI really isn't helping

5 The Google Pixel 10 is the brand's 'most competitive phone yet' — and it just hit a record-low price at Amazon

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • Express VPN uncovers 3

  • Leaked data points included voice and text messages, and even private audio recordings lasting up to 4 hours

  • When you purchase through links on our site, we may earn an affiliate commission

  • Express VPN uncovered massive amounts of AI chatbot leaked data

  • If you heard that up to 3

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.