2026 RentAHuman — ~187,714 emails (misconfiguration; API exposure)
Data compromised
Email addresses (bulk user list); other fields per forensic confirmation
Technical writeup
Public reporting in mid-March 2026 described a security failure on the RentAHuman AI-agent marketplace in which a researcher reportedly extracted a large user email dataset—on the order of 187,714 addresses—after finding insufficient access controls or misconfiguration (e.g., exposed API/token paths allowing rapid bulk retrieval). The incident was widely cited in AI-security discussions as an example of weak secret management and RBAC in fast-moving AI platforms. Treat operational details as summarized from industry analyses until official primary notices are located.
Root cause
Misconfiguration / weak access controls; exposed API or credential hygiene per reporting