Academic researchers demonstrated that large language models (LLMs) can automate deanonymization by building profiles from a person’s historical online comments and other unstructured “digital exhaust,” then linking those profiles across platforms even when different pseudonyms are used. In limited testing, the approach reportedly achieved 99% precision when linking Hacker News accounts to LinkedIn profiles by correlating signals such as vocabulary, location hints, hobbies, and other biographical clues, undermining the long-held assumption that pseudonymity is protected by the effort required to unmask individuals.
Separate reporting highlighted real-world privacy exposure consistent with these risks: the AI comic-generation service KomikoAI disclosed a breach exposing ~1M unique email addresses along with names, user posts, and AI prompts, enabling prompts to be mapped back to specific identities. Other items in the set were not about LLM deanonymization and instead covered a weekly security news roundup, geopolitical warnings about potential Iranian cyber reprisals, generic IoT security advice, an interview about DEF CON/government relations, an investigation into the Kimwolf botnet operator, and U.S. tech-policy legislation—none of which materially advanced the specific deanonymization research story.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
Academic research reported on March 2, 2026 found that large language models can automate deanonymization by profiling users from prior comments and linking pseudonymous accounts across platforms. The reported tests claimed up to 99% precision when matching Hacker News accounts to LinkedIn profiles.
In February 2026, the AI-powered comic generation platform KomikoAI experienced a breach. Exposed data included 1 million unique email addresses, user names, user posts, and AI prompts that could be linked back to specific email addresses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.