2026 ChatMinerva — admin-privilege intrusion; user DBs + AI chats; hashed passwords
Data compromised
Per user notice: names; DOB/gender/profile/bio when provided; email; password hashes (not plaintext); conversations with the AI model. Census and exact intrusion date not published. Garante notification and criminal complaint planned.
Technical writeup
Verified ChatMinerva user notice — reported September 18, 2026 (CybersecItalia / Cyber News). Platform told subscribers an unidentified external party maliciously accessed the service with administrative privileges and reached user databases. Potentially involved: identity/profile fields, emails, securely hashed passwords, and model conversations. Operator blocked the anomaly, hardened controls, plans Garante Privacy notice and police complaint. No published headcount or confirmation of exfiltration vs access-only. recordsAffected 0; companyConfirmed true.
Root cause
Unidentified external party obtained administrative privileges and accessed user databases (platform user notice)