Submit incident
Documented

An AI Porn Platform Left Two Million Nonconsensual Images Exposed on the Open Internet

January 1, 2025
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiaaic:AIAAIC2141View source ↗
LinkedInX

What happened

In 2025, an erotic roleplay chatbot and AI image generator called Secret Desires, operated by Playhouse Media LLC, left a cloud database containing close to two million images and videos publicly accessible without a password. The collection included personal photos women had never submitted to the platform: real photographs sourced from yearbooks and social media, alongside explicit deepfake-style content generated from those same faces. Names, schools, and workplaces appeared in the metadata alongside the imagery.

The exposure was discovered by 404 Media, which found that the database had been sitting open on the public internet for months before Playhouse Media took it offline shortly after journalists notified the company. Anyone who found the endpoint during that window could have copied, downloaded, or redistributed the contents with no trace left behind. The dataset appears to have grown through a face-swap feature the platform offered, which allowed users to apply real women's photographs to explicit templates and save the outputs back to the same storage bucket the breach exposed.

The harms are not hypothetical. Nonconsensual intimate imagery of real, identifiable people was accessible to anyone who looked. The metadata pairing names with explicit content created a directory well suited to targeted harassment, doxxing, and extortion. Victims had no notice the images existed, no mechanism to remove them, and no way to know who had downloaded copies before the database was closed. Images that leave a server remain in circulation regardless of what the operator does afterward.

Playhouse Media's practices made this scale of exposure possible. The company collected training data without disclosing its sources, appears to have included minors' yearbook photos in the corpus, and ran a face-swap pipeline on biometric likenesses it had no authority to use. There was minimal content-safety oversight and no transparency with users about how uploads were stored or processed. Basic access controls, the kind that would have required a credential to reach production storage, were absent entirely.

The incident illustrates a specific accountability gap: when a system generates, stores, and distributes nonconsensual intimate imagery at scale, victims have almost no way to establish what was created, when, by whom, or how widely it spread. A provable record of what a system did, including which images were generated, how the training corpus was assembled, and who had access to stored outputs, would at minimum give regulators and victims a factual basis to act on. Without it, operators can collect and expose intimate imagery of millions of people and face consequences only after a journalist finds the open bucket.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AIAAIC Repository
Also catalogued in
An AI Porn Platform Left Two Million Nonconsensual Images Exposed on the Open Internet
2025