Last updated 1 month ago
Plantake, the developer of the Quitbro porn addiction management application, experienced a data breach in February 2026 that exposed 22,874 unique user records. The breach involved the compromise of sensitive user data from the application's systems, though the specific date of internal discovery remains unconfirmed. The incident was publicly disclosed in February 2026, with the company failing to respond to multiple contact attempts regarding the event.
The breach resulted in unauthorized access to Quitbro's user database, leading to the exfiltration of email addresses, user birth years, responses to personalized application questions, and the last recorded relapse times for each affected individual. The attack vector involved unauthorized access to the application's data storage systems, though the specific technical method of intrusion was not detailed in the available reporting. No threat actor has been attributed to this incident at this time.
Plantake has not issued any public statements, breach notifications, or remediation updates regarding this incident. The company's lack of response to external inquiries has left the user community without official confirmation or guidance on potential risks stemming from the exposure of their sensitive behavioral health data.
The Quitbro breach demonstrates critical failures in data protection for applications handling sensitive behavioral and health-related information, where even anonymized or pseudonymized data like relapse timestamps and questionnaire responses can create significant privacy risks. The incident highlights the necessity for robust access controls and encryption around user profile data in wellness applications, particularly when companies operate without transparent communication protocols for security incidents. The complete lack of response from Plantake underscores the operational security risk posed by companies that fail to establish incident response plans and stakeholder communication channels, leaving users vulnerable without recourse or information.
Sign in to join the discussion.
Company
Industry
Disclosed
Records Affected
Attack Vector
Industry
Attack Vector