Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Data Breaches

calai.app Data Breach Exposes Three Million User Records

🇺🇸 United States - calai.app (Cal AI)

March 9, 2026
Reading Time: 1 min read
calai.app Data Breach Exposes Three Million User Records

Cal AI App, a mobile calorie and health tracking application, has allegedly been compromised, resulting in the exposure of data belonging to approximately 3 million subscribers. The incident, recently disclosed on a cybercrime forum, reportedly stems from severe security misconfigurations within the application’s infrastructure. The database dump was allegedly made possible because the app’s tables—including subscription data—could be accessed and read without authentication.

The allegedly compromised data is contained within a 14.59 GB database dump and includes highly sensitive personal, financial, and health-related information. According to the actor, the exposed data includes:

  • Email addresses (including approximately 1 million Apple Private Relay addresses)

  • First and last names (for approximately 300,000 users with configured social profiles)

  • Dates of birth

  • Genders

  • Height and weight metrics (including historical tracked weight over time)

  • Exercise goals and target metrics

  • Logged meals and specific eating habits (including times of day users eat)

  • Purchased subscriptions and App Store transaction IDs

  • Third-party integration metrics (Superwall, Klaviyo, AppsFlyer)

  • User referral code conversion information

Tags: calai.appdata-breachDatabase ExposureHealth ApplicationHealth Data LeakMobile App SecurityPrivacy IncidentUnited States
ShareTweet

Related Posts

Uganda Ministry of Agriculture MAAIF Suffers Data Breach
Data Breaches

Uganda Ministry of Agriculture MAAIF Suffers Data Breach

April 27, 2026
Ellipal Cryptocurrency Wallet Suffers Alleged Data Breach
Data Breaches

Ellipal Cryptocurrency Wallet Suffers Alleged Data Breach

April 27, 2026
BlackSexFinder Adult Platform Suffers Massive Data Breach
Data Breaches

BlackSexFinder Adult Platform Suffers Massive Data Breach

April 27, 2026
Jeff Honeycutt Insurance Agency Data Breach Exposes Client Info
Data Breaches

Jeff Honeycutt Insurance Agency Data Breach Exposes Client Info

April 27, 2026
FFWPU and Tongil Group Face Extensive Data Breach
Data Breaches

FFWPU and Tongil Group Face Extensive Data Breach

April 27, 2026
Terra West Management Services Suffers Major Data Breach
Data Breaches

Terra West Management Services Suffers Major Data Breach

April 24, 2026
Next Post
Côté Sushi Data Breach Exposes Over 1 Million Customer Records

Côté Sushi Data Breach Exposes Over 1 Million Customer Records

Rapikom Venezuela Suffers Data Breach

Rapikom Venezuela Suffers Data Breach

Recommended Stories

Reported Data Leak at Equis Financial Exposes Extensive Client Information

Reported Data Leak at Equis Financial Exposes Extensive Client Information

November 12, 2024
Bank Syariah Indonesia Customer Credentials Allegedly Leaked via Stealer Logs

Bank Syariah Indonesia Customer Credentials Allegedly Leaked via Stealer Logs

June 5, 2025
Appsim.vn Data Breach Exposes Over 1 Million Users

Appsim.vn Data Breach Exposes Over 1 Million Users

November 12, 2025

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?