✓ Connection Protected ISP: Anthropic, PBC (216.73.217.135)

Cal AI Data Breach: Over 3 Million Users Exposed

Cal AI, the viral calorie-tracking app endorsed by MrBeast and other influencers, is facing serious data breach allegations.

Cal AI Data Breach

A hacker claims to have stolen personal records belonging to more than 3 million users. Leaked files are already circulating on dark web forums and Telegram channels.

The app lets users snap a photo of their food to count calories using artificial intelligence. It has been downloaded over 15 million times.

Just one week before the breach surfaced, Cal AI completed its acquisition of MyFitnessPal, the fitness platform that suffered its own massive breach in 2018.

How the Cal AI Data Breach Happened

On March 9, 2026, a hacker going by “vibecodelegend” posted on BreachForums claiming to have extracted roughly 15 GB of data from Cal AI’s backend.

Cal AI Data Breach Claim
Cal AI Data Breach Claim (Source: Hackread)

The attacker says they exploited an unauthenticated Google Firebase database, meaning no login credentials were needed to access user records.

According to the hacker, the stolen dataset includes:

  • Full names and usernames
  • Over 2.8 million unique email addresses
  • Dates of birth, genders, heights, and weights
  • Social media profiles
  • PIN codes and subscription details
  • Meal logs, calorie tracking data, and times of day users eat
Some of the Exposed Data
Some of the Exposed Data (Source: Hackread)

Security researchers reviewed the samples and confirmed they appear legitimate. One alarming detail: the dataset contains records of a user born in 2014, raising child data protection concerns.

 
Your Connection is Exposed

Hide Your Digital Fingerprint

IP Address 216.73.217.135
Location Columbus, Ohio
ISP Anthropic, PBC
Secure My Connection Now
Limited Time: 85% Off + 3 Months FREE
 

TROYPOINT Tip: Protect your identity and personal info from a data breach by using Aura Identity Theft Protection which is TROYPOINT’s recommended identity theft protection.

Aura Identity Theft Protection Review

Cal AI’s Response

As of publication, Cal AI has not responded to press inquiries about the alleged breach. This silence is concerning given that the company just acquired MyFitnessPal, meaning they now control data from two platforms with a history of security failures.

Cal AI Website
Cal AI Website

If you use Cal AI or recently created an account, take action right away. Change passwords on any accounts tied to the same email you used for the app. Enable two-factor authentication wherever possible, and watch for phishing emails that reference your health data.

Final Thoughts

This won’t be the last data breach involving sensitive health information. As more apps collect detailed records about our bodies and daily routines, the target on these platforms only grows.

I recommend checking Have I Been Pwned to see if your email has appeared in this or any other known breach.

For more details on this story, refer to the report from Hackread.

We want to know your thoughts. What do you think about this story? Let us know in the comment section below!

Be sure to stay up-to-date with the latest streaming news, reviews, tips, and more by following the TROYPOINT Advisor with updates weekly.

This page includes affiliate links where TROYPOINT may receive a commission at no extra cost to you. Many times, visitors will receive a discount due to the special arrangements made for our fans. Learn more on my Affiliate Disclaimer page.

 

Exclusive Surfshark Discount

Your online activity is currently monitored by your ISP, app/addon/IPTV developers, government agencies, and the websites you visit.

  • Become 100% anonymous while streaming and downloading.
  • Use on Unlimited Devices & share 1 account with the entire family.
  • Save 85% with the 24-Month Plan + Get 3 FREE Months.
Claim Deal Here
 

Leave a Comment

Your email address will not be published. Required fields are marked *

SURFSHARK VPN
ONLY $.07/DAY!

X
TROYPOINT Last Chance for VPN