komiko.app data breach

komiko.app

What Happened

In February 2026, the AI-powered comic generation platform KomikoAI (komiko.app) suffered a critical data breach affecting over 1 million users. The breach exposed a complete database dump containing 1.06 million compromised accounts with personally identifiable information including email addresses, usernames, full names, profile pictures, and user-generated content along with the AI prompts used to create it. Most critically, the leaked dataset included active Google OAuth tokens and session tokens, which attackers could use to hijack accounts and access linked Google services without requiring passwords. The threat actor published the breach on an underground forum in early March 2026, claiming the incident occurred in February after the platform allegedly ignored extortion demands. The exposure poses severe risks including account takeover, targeted phishing and blackmail campaigns (particularly threatening to users who generated sensitive content), credential stuffing attacks, and potential identity theft.

Compromised Assets

  • email
  • password
  • full name
  • phone

Check your company's
exposed credentials

Enter your work email to instantly access a free account
and see your company’s exposed credentials.

Related Breaches