Thousands of AI-built apps exposed sensitive corporate and personal data, researchers found

Thousands using Lovable, Base44, Replit and Netlify have inadvertently exposed their sensitive data.

Thousands of AI-built apps exposed sensitive corporate and personal data, researchers found

TL;DR

  • AI coding tools allow employees without technical training to create and publish applications publicly.
  • These applications often lack proper security oversight and access controls, leading to data leaks.
  • Researchers identified hundreds of thousands of publicly accessible assets built with AI coding tools, with thousands containing sensitive corporate data.
  • Exposed data includes medical records, financial information, customer service conversations, patient data, and internal company documents.
  • Many of these tools default to public accessibility unless manually changed to private.
  • Some companies using these tools are investigating and securing their exposed applications after being notified.
  • Security researchers found phishing sites built using one of these tools that impersonated well-known brands.