Data leak

Sears Home Services AI Chatbot Data Exposure - 3.7M Records, 4.3TB

πŸ“… 2026-02-03
Primary Source β†—

Incident Details

On February 3, 2026, security researcher Jeremiah Fowler discovered three unsecured publicly exposed databases during routine Shodan scans, containing 4.3 terabytes of data linked to Sears Home Services (‘Samantha’ and ‘KAIros’ AI chatbot systems). The databases were made inaccessible the following day after responsible disclosure to Transformco. The exposure included approximately 3.7 million records: 2.1 million chat transcripts, 200,000 scheduling logs, and 1.4 million audio recordings of customer service interactions from 2024-2026. Data was in English and Spanish and contained customer names, physical addresses, email addresses, phone numbers, and details about products, services, repairs, and delivery appointments. The researcher noted that the chatbot continued recording for up to 4 hours in cases where customers did not properly hang up, capturing unrelated personal conversations. Transformco is the parent company that owns Sears Home Services after the Sears bankruptcy restructuring.

Technical Details

Initial Attack Vector
Misconfiguration: Transformco (Sears Home Services parent) left three cloud storage buckets containing AI chatbot logs, audio recordings, and scheduling data publicly accessible without authentication

Timeline

  1. 2026-02-03 Breach occurred
  2. 2026-02-03 Publicly disclosed