Egidio
Case file · August 24, 2026

Klark.ai: up to 500,000 people potentially exposed

A hacker calling themselves 0xSec claims over 140 GB from 4 databases at Klark.ai, a French AI platform for customer service teams: support conversations, a handful of IBANs, API keys and secrets. Not confirmed by the company.

⚠️ Claimed, not confirmed. What's known comes from the hacker's own post and its coverage by Cyberattaque.org, an independent French breach observatory, on the morning of August 24, 2026. Klark.ai had not, to our knowledge, publicly confirmed or denied the claim at the time of writing.

The numbers, and what backs them

≈ 500,000
People potentially affected — an estimate complicated by deduplication across the 4 databases.
Cyberattaque.org, based on the claim.
140 GB
Total volume of data the hacker claims to have obtained, spread across 162 CSV files.
0xSec's claim.
4
Separate databases claimed as exfiltrated, some individually exceeding 2 million rows.
0xSec's claim.
18
Klark.ai client companies named in Cyberattaque.org's coverage as having the highest conversation volume present — without this implying their own systems were compromised.
Cyberattaque.org.

Timeline

CLAIMED
August 24, 2026, 6:18 AM CET
A hacker calling themselves 0xSec posts a claim against Klark.ai: 4 databases, over 140 GB, 162 CSV files.
OBSERVED
August 24, 2026, 6:41 AM CET
Cyberattaque.org publishes and updates its analysis of the claim, detailing the data types involved and the client companies with the highest conversation volume.

🔑What the 4 databases reportedly contain

Names, emails and phone numbers; hashed passwords (not plaintext); full customer support conversations; a handful of IBANs; technical logs; and, notably for a consumer-facing leak, API keys and secrets. If real and still valid, these technical credentials could in theory allow access to client companies' own systems — a distinct risk from the one facing individuals whose conversations may have leaked.

What this means for you

If you've exchanged messages with the customer support team of a company that may use Klark.ai (among those named: Showroomprivé, BUT, Back Market, Vestiaire Collective, Getaround, Cultura and others), the actual content of your conversation — not just your email address — could have leaked if the claim holds up. Be alert to any message posing as customer support that references a past conversation to request sensitive information or payment. See also our case file From leak to scam.

🔒 Passwords are reportedly hashed, not plaintext: the immediate risk of direct account takeover is lower than in a plaintext-password leak. The main risk here is exposed conversation content and identity theft using precise personal data.

Frequently asked questions

Is the Klark.ai breach confirmed?

No, not to our knowledge at the time of writing.

Could my conversation with a customer service team at a company like Showroomprivé or Back Market be affected?

Possibly, if that company uses Klark.ai — but its name appearing in the claimed databases doesn't mean its own systems were compromised.

Why would API keys be in a consumer data leak?

Klark.ai is a B2B tool connected to its clients' systems; leaked keys pose a distinct risk to those companies themselves.

📌 Last checked: August 24, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio — The Threat Laboratory, "Klark.ai: up to 500,000 people potentially exposed," egidio.app/en/laboratoire/klark-ai-customer-service-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.