Cal AI Breach Exposes 3 Million Users' Meal Logs and Personal Data
In March 2026, an unauthenticated Firebase misconfiguration leaked 14.59GB from Cal AI, a calorie-tracking app owned by MyFitnessPal — emails, names, birth dates, and intimate meal logs of 3+ million users. Here's what happened and what to do.
The Breach Cal AI markets itself as an AI weight-loss companion: point your camera at a plate of food, and the app estimates calories, macros, and progress. To do that, it holds some of the most personal data a consumer app can collect — what you eat, how much you weigh, what your body looks like, and what your health goals are. In March 2026, threat actor "vibecodelegend" leaked a compressed dataset on a cybercrime forum containing records for roughly 3 million users — about 14.59 GB of data. The leak came from an unauthenticated, misconfigured Google Firebase backend database: no login, no firewall on the bucket, just data waiting for anyone who knew where to look. What Was Exposed The exposed records included: Email addresses and full names
Dates of birth
Physical attributes — height, weight, and the body-metric data users log to track progress
Detailed meal logs — every meal photographed and estimated, a daily diary of eating habits
Macronutrient targets — the nutritional plans users set for themselves
Subscription and transaction details There are few datasets more intimate than a meal log. Combined with weight and birth date, it reveals not just who you are but how you live — information that's gold for targeted scams, insurance profiling, and the kind of AI-enhanced phishing we've documented in detail. Why Health Data Keeps Leaking A misconfigured database bucket is an error, not a malicious plot — but it's a predictable one. Health and fitness apps are often built fast, funded on growth metrics, and treated like social apps while holding data that should be treated like medical records. When Amazon's One Medical breached elderly patients' Medicare data, the lesson was that healthcare incumbents leak too; Cal AI shows the same risk profile in the newer, AI-first generation of wellness apps — apps that collect even more data, with even less regulatory oversight. The pattern is consistent with the state health-exchange data leaks: sensitive health information lives in systems designed for convenience, and the consequences fall entirely on the people whose data was taken. What to Do Assume your data was in the dump. If you've used Cal AI (or its parent's ecosystem), treat your email as compromised: expect phishing, and change passwords on any account that reused it.
Watch for targeted scams. Meal-log and body-data dumps power highly personalized social-engineering campaigns. Be suspicious of anyone referencing your weight, diet, or subscriptions.
Freeze your credit if payment details were involved. Subscription and transaction data can feed account-takeover attempts.
Audit your health apps. Every app that stores your weight, diet, or biometrics is a risk. Delete the ones you don't actively use, and prefer apps that process data on-device. The Pattern Cal AI is the third major health-data exposure in this reporting cycle, and it won't be the last. The data is uniquely sensitive, the defenses are routinely weak, and the democratized AI-fraud ecosystem is ready to weaponize it. The practical lesson: the app that knows your body is also the app most worth protecting — and the least worth trusting with more than it needs.