A threat actor using the handle "vibecodelegend" has claimed to have breached Cal AI, an AI-powered calorie-tracking app, and leaked a dataset of roughly 14.6–15 GB that allegedly contains information on more than 3 million users. Reporting indicates the data may have been obtained from a misconfigured Google Firebase instance, and researchers cited in coverage said their analysis suggests the leaked dataset appears legitimate, though Cal AI had not publicly confirmed the incident at the time of reporting.
The exposed data reportedly includes multiple files containing users’ full names, dates of birth, gender, and detailed health/fitness-related records such as height/weight entries, goals, and macronutrient targets, along with settings, subscription details, and transaction IDs. Researchers warned that the combination of contact and profile data could enable targeted social engineering and profiling of affected users; coverage also noted Cal AI’s rapid growth and visibility (including influencer sponsorship) and referenced its reported acquisition by MyFitnessPal.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
At the time the incident was reported publicly, Cal AI had not confirmed whether a breach had occurred. Reports also said the exposed data may have originated from a misconfigured Google Firebase instance.
Cybernews researchers reviewed the exposed Cal AI data and assessed it as likely authentic. They warned that the combination of contact details and health-related profile information could support profiling and targeted social engineering.
A threat actor using the handle "vibecodelegend" allegedly breached the AI calorie-tracking app Cal AI and released roughly 14.6-15 GB of user data online. The leaked dataset was reported to affect more than 3 million users and included personal, behavioral, subscription, and transaction-related information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.