Researchers reported that Bondu’s AI plush toy exposed a public-facing web console that allowed anyone with a Gmail account to access roughly 50,000 private chat transcripts between children and the toy, without needing to bypass authentication. The exposed logs reportedly included sensitive personal details (e.g., names, birth dates, family information, and intimate conversations), creating potential real-world safety risks if misused. Bondu took the console offline shortly after disclosure, then relaunched it with authentication; the company stated fixes were completed within hours, claimed no evidence of other access, and said it engaged a security firm and added monitoring.
Separately, the UK Information Commissioner’s Office (ICO) opened a formal investigation into X and its Irish subsidiary over reports that the Grok AI assistant was used to generate nonconsensual sexual images, examining whether personal data was processed lawfully and whether safeguards were adequate to prevent harmful manipulated imagery—particularly where children may be impacted. A third piece is a general commentary on children’s data protection in an AI-saturated environment; it provides contextual privacy concerns but does not add incident-specific facts, IOCs, or technical findings tied to either the Bondu exposure or the Grok regulatory probe.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
After the exposure was disclosed, Bondu reportedly took the console offline within minutes and later relaunched it with authentication. The company’s CEO said the fixes were completed within hours and claimed there was no evidence of other access.
Two researchers discovered that Bondu’s public-facing web console allowed anyone with a Google account to access roughly 50,000 private chat transcripts between children and the AI plush toy, exposing names, birth dates, family details, and intimate conversations without any hacking.
The UK Information Commissioner’s Office formally opened an investigation into X and its Irish subsidiary, examining whether X Internet Unlimited Company and xAI processed personal data lawfully and had adequate safeguards to prevent Grok from generating nonconsensual sexual images, including risks involving children.
French prosecutors searched X’s Paris offices as part of a criminal investigation into whether Grok generated child sexual abuse material and Holocaust denial content. They also summoned Elon Musk, CEO Linda Yaccarino, and other employees for interviews scheduled in April.
On January 7, the UK Information Commissioner’s Office said it contacted X and xAI to request urgent information about compliance measures after reports that Grok was used to create sexually explicit images using individuals’ personal data.
In January 2026, the European Commission launched a formal investigation into whether X properly assessed Digital Services Act risks before deploying Grok after the assistant was reportedly used to generate sexually explicit images.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.