The numbers, and what backs them
Timeline
🔑What the 4 databases reportedly contain
Names, emails and phone numbers; hashed passwords (not plaintext); full customer support conversations; a handful of IBANs; technical logs; and, notably for a consumer-facing leak, API keys and secrets. If real and still valid, these technical credentials could in theory allow access to client companies' own systems — a distinct risk from the one facing individuals whose conversations may have leaked.
What this means for you
If you've exchanged messages with the customer support team of a company that may use Klark.ai (among those named: Showroomprivé, BUT, Back Market, Vestiaire Collective, Getaround, Cultura and others), the actual content of your conversation — not just your email address — could have leaked if the claim holds up. Be alert to any message posing as customer support that references a past conversation to request sensitive information or payment. See also our case file From leak to scam.
Frequently asked questions
Is the Klark.ai breach confirmed?
No, not to our knowledge at the time of writing.
Could my conversation with a customer service team at a company like Showroomprivé or Back Market be affected?
Possibly, if that company uses Klark.ai — but its name appearing in the claimed databases doesn't mean its own systems were compromised.
Why would API keys be in a consumer data leak?
Klark.ai is a B2B tool connected to its clients' systems; leaked keys pose a distinct risk to those companies themselves.
Related reading
Egidio — The Threat Laboratory, "Klark.ai: up to 500,000 people potentially exposed," egidio.app/en/laboratoire/klark-ai-customer-service-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.