Intimeros: AI girlfriend review site's secrets were exposed to the world for three weeks

Intimeros: AI girlfriend review site's secrets were exposed to the world for three weeks

Test Site Oversight Exposes Intimeros’ Editorial Strategy to Public Scrutiny

A routine website redesign at Intimeros, a platform that reviews and rates AI companions, led to a three-week security lapse after a test site was left unprotected and publicly accessible. The incident, reported by Mia Morin, the company’s Editor & AI Quality Analyst, occurred when a colleague disabled password protection to showcase work to a client but failed to re-enable it.

Compounding the issue, the test site lacked a robots.txt file, allowing Google to index its contents. Since the test environment was linked to the live production database, unpublished reviews, pricing details, and internal product notes were exposed. While no user data was compromised, the breach risked revealing Intimeros’ editorial strategy to competitors.

Morin discovered the oversight after noticing the test site in search results. The company responded by reinstating password protection, blocking search engine indexing, and rotating system access keys. Intimeros has since tightened security protocols, treating test environments with the same safeguards as its production site and implementing weekly automated scans to detect exposed pages.

The incident underscores the risks of unsecured staging environments, particularly when connected to live data. Simple oversights like disabled authentication or missing crawl directives can lead to unintended public exposure.

Source: https://www.theregister.com/security/2026/08/27/ai-girlfriend-review-sites-secrets-were-exposed-to-the-world-for-three-weeks/5293064

Intimeros TPRM report: https://www.rankiteo.com/company/intimeros

"id": "int1787862265",
"linkid": "intimeros",
"type": "Breach",
"date": "8/2026",
"severity": "50",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'industry': 'AI Companion Reviews and Ratings',
                        'name': 'Intimeros',
                        'type': 'Company'}],
 'attack_vector': 'Misconfiguration',
 'data_breach': {'personally_identifiable_information': 'No',
                 'sensitivity_of_data': 'Medium (competitive intelligence)',
                 'type_of_data_compromised': 'Editorial content, pricing '
                                             'details, internal product notes'},
 'description': 'A routine website redesign at *Intimeros*, a platform that '
                'reviews and rates AI companions, led to a three-week security '
                'lapse after a test site was left unprotected and publicly '
                'accessible. The incident occurred when a colleague disabled '
                'password protection to showcase work to a client but failed '
                'to re-enable it. The test site lacked a *robots.txt* file, '
                'allowing Google to index its contents. Since the test '
                'environment was linked to the live production database, '
                'unpublished reviews, pricing details, and internal product '
                'notes were exposed. While no user data was compromised, the '
                'breach risked revealing Intimeros’ editorial strategy to '
                'competitors.',
 'impact': {'data_compromised': 'Unpublished reviews, pricing details, '
                                'internal product notes',
            'operational_impact': 'Exposure of editorial strategy to '
                                  'competitors',
            'systems_affected': 'Test site linked to live production database'},
 'investigation_status': 'Resolved',
 'lessons_learned': 'The incident underscores the risks of unsecured staging '
                    'environments, particularly when connected to live data. '
                    'Simple oversights like disabled authentication or missing '
                    'crawl directives can lead to unintended public exposure.',
 'post_incident_analysis': {'corrective_actions': 'Reinstated password '
                                                  'protection, blocked search '
                                                  'engine indexing, rotated '
                                                  'system access keys, '
                                                  'tightened security '
                                                  'protocols for test '
                                                  'environments, implemented '
                                                  'weekly automated scans',
                            'root_causes': 'Disabled password protection, '
                                           'missing robots.txt file, test '
                                           'environment linked to live '
                                           'production database'},
 'recommendations': 'Treat test environments with the same safeguards as '
                    'production sites, implement automated scans to detect '
                    'exposed pages.',
 'references': [{'source': 'Mia Morin (Editor & AI Quality Analyst at '
                           'Intimeros)'}],
 'response': {'containment_measures': 'Reinstated password protection, blocked '
                                      'search engine indexing, rotated system '
                                      'access keys',
              'enhanced_monitoring': 'Weekly automated scans to detect exposed '
                                     'pages',
              'remediation_measures': 'Tightened security protocols for test '
                                      'environments, implemented weekly '
                                      'automated scans to detect exposed '
                                      'pages'},
 'title': 'Test Site Oversight Exposes Intimeros’ Editorial Strategy to Public '
          'Scrutiny',
 'type': 'Data Exposure',
 'vulnerability_exploited': 'Unprotected test environment, missing robots.txt '
                            'file'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.