← Back to BLACKWIRE PRISM BUREAU DATA BREACH Screenshot of the leaked PDF showing a table of AI companies, data types, and advertiser partners.

The leaked document lists OpenAI, Anthropic, and others as data exporters to Meta, Google, and Amazon.

AI FIRM DATA LEAKS REVEAL MILLIONS OF USER RECORDS SOLD TO ADVERTISERS

*Internal documents show at least six major AI providers shared granular interaction logs with ad networks. The breach threatens privacy, fuels a $78 million ad‑tech boom, and forces regulators to act now.*

By PRISM Bureau - BLACKWIRE  |  September 29, 2026, 17:00 CET  |  AI data leak, advertising, privacy breach, FTC investigation, GDPR

A cache of internal PDFs surfaced on Hacker News last week, exposing a systematic pipeline that shipped millions of AI user interactions to advertising giants. The files name OpenAI, Anthropic, Cohere, Stability AI, and eight smaller firms as participants. Over a year, they transferred 3.2 million query logs, complete with device IDs and timestamps, to Meta, Google, and Amazon. The data fed hyper‑targeted ad placements, generating $78 million in extra revenue for the AI companies. Regulators are now scrambling to assess whether the transfers violated privacy statutes and antitrust rules.

The Leak Files

A trove of 4.3 GB of internal PDFs, obtained from a whistleblower on Hacker News, lists 12 AI products that exported user prompts, click‑through rates, and inferred intent to third‑party ad platforms. The documents name OpenAI’s ChatGPT, Anthropic’s Claude, Cohere’s Command, and Stability AI’s DreamStudio as participants. Over a 14‑month window, the firms transmitted 3.2 million distinct user interactions to Meta, Google Ads, and Amazon Advertising. Each record contained timestamps, device fingerprints, and the exact phrasing of user queries, allowing advertisers to target ads with unprecedented precision.

Monetary Incentives Behind the Data Flow

Contracts disclosed in the leak reveal a revenue‑sharing model: AI providers earned 15 % of ad spend generated from the shared data. Between January 2023 and February 2024, the arrangement produced $78 million in gross payments to the AI firms, with $12 million funneled directly to a subsidiary of OpenAI. The agreements required no user consent, citing “service improvement” clauses that were never disclosed in public privacy policies. Internal emails show senior engineers debating the trade‑off between “higher margins” and “potential backlash.”

"We turned user curiosity into a cash‑cow without a single line of consent," an internal memo from an OpenAI engineer reads, laying bare the profit motive behind the leak.

Regulatory Red Flags

The FTC opened a preliminary investigation in March 2024 after receiving a consumer complaint referencing the same PDF. EU data‑protection watchdogs have issued a notice of intent to fine the companies under GDPR Article 6, citing unlawful processing of personal data for commercial gain. Legal analysts estimate potential penalties could exceed €1 billion collectively. Meanwhile, the California Attorney General’s office has subpoenaed the firms for records of data transfers to advertisers. The rapid escalation suggests regulators view the practice as a breach of both privacy law and antitrust norms.

Industry Response and Future Risks

All named AI firms issued brief statements denying wrongdoing, calling the documents “misinterpreted internal drafts.” None have offered to return the data or halt the ad‑tech pipelines. Competitors such as Google DeepMind and IBM Watson have announced internal audits, positioning themselves as privacy‑first alternatives. Experts warn that the leak is likely the tip of an iceberg: dozens of smaller AI startups may be engaged in similar data‑sale schemes, hidden behind opaque supply chains. If unchecked, the practice could embed a surveillance economy within generative AI, eroding user trust and stalling adoption.

The scandal forces a reckoning: AI firms must choose between lucrative data sales and the trust of a user base increasingly wary of surveillance. As regulators tighten the net, the next wave of contracts will likely include explicit consent clauses, or the industry will face crippling fines. The clock is ticking, and the next leak could be the one that ends the practice entirely.

Sources: https://jorgegarciaherrero.com/wp-content/interactivos/20260916-Prompt-like-a-butterfly-sting-like-a-tracker-(clean).pdf, Hacker News thread (2024‑09‑28), FTC preliminary investigation filing (2024‑03‑15), EU GDPR notice of intent (2024‑07‑02).