AI girlfriend review site's secrets were exposed to the world for three weeks
- ID
- 18791
- Status
- summarized
- Published
- 28 Aug 2026, 3:10 AM
- Fetched
- 28 Aug 2026, 5:02 AM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/08/27/ai-girlfriend-review-sites-secrets-were-exposed-to-the-world-for-three-weeks/5293064
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 4.5
- Created
- 28 Aug 2026, 6:10 AM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
Intimeros, a site that reviews AI companions, left a staging site publicly accessible for three weeks after a colleague disabled password protection to show a client. The staging site was connected to the live production database, exposing unpublished reviews, prices, and editorial strategy notes to anyone, and was indexed by Google before editor Mia Morin noticed and locked it down.
Why it matters
If you run staging or preview environments connected to production databases, check right now whether they require authentication and are blocked from search indexing. The specific failure here—disabling protection for a demo and forgetting, plus no robots.txt—turned internal editorial content into publicly discoverable pages. Treat staging access controls as production-grade and add automated scans for exposed pages.
Discussion angle
How do you isolate staging from production data without duplicating infrastructure costs, and what automated checks do you run to catch accidentally exposed staging URLs?