← Rentahuman

2026 RentAHuman — ~187,714 emails (misconfiguration; API exposure)

2026 187.7K records affected Share on X

Data compromised

Email addresses (bulk user list); other fields per forensic confirmation

Technical writeup

Public reporting in mid-March 2026 described a security failure on the RentAHuman AI-agent marketplace in which a researcher reportedly extracted a large user email dataset—on the order of 187,714 addresses—after finding insufficient access controls or misconfiguration (e.g., exposed API/token paths allowing rapid bulk retrieval). The incident was widely cited in AI-security discussions as an example of weak secret management and RBAC in fast-moving AI platforms. Treat operational details as summarized from industry analyses until official primary notices are located.

Root cause

Misconfiguration / weak access controls; exposed API or credential hygiene per reporting

References