-
A forum actor claims to have stolen data linked to about 7,300 Sora2U user accounts.
-
The alleged dataset contains emails, usernames, names, password hashes, and other account details.
-
Sora2U, the popular AI video generation platform, has not confirmed a breach, while the leaked data has not received independent verification.

A threat actor has allegedly leaked a database containing information linked to thousands of Sora2U users. The actor claims the database came from Sora2U, an AI video generation and resource platform.
The alleged leak reportedly contains information connected to about 7,300 unique user accounts. The actor also shared a sample of the alleged stolen data on a forum.
However, no independent source has confirmed that the data came from Sora2U. The platform has also not publicly confirmed that attackers broke into its systems. This means the incident remains an alleged data breach and not a confirmed security event.
The claim still raises concerns because the reported dataset contains several types of user information. That information could include details that users may not want exposed online.
Details of the Alleged Data Leak
The alleged dataset reportedly contains several pieces of information linked to Sora2U accounts. These records include user IDs, email addresses, names, and usernames.
The data also reportedly contains password hashes, profile images, and user biographies. Other fields allegedly show whether users completed email verification for their accounts. The value of personal data is evident in other dark web listings, a threat actor has claimed to be selling data of 40 million Indian women.
The dataset also reportedly includes referral codes and account creation timestamps. Account update timestamps are also said to appear in the leaked information. The combination of these records could provide a detailed view of individual user accounts. However, the presence of password hashes does not mean that plain passwords appeared in the dataset.
Password hashes use a protected format instead of showing the original password directly. Still, attackers could try to crack weak passwords if they obtain the hashes.
Users who reuse the same password across different services could face additional risks. The leaked records could also give attackers useful information for targeted phishing attempts.
Criminals could use names and email addresses to create messages that look more believable. They could also combine usernames, profile details, and other information during social engineering attacks.
However, the available information does not confirm that attackers have used the data this way. It only shows the possible risks linked to the types of information allegedly exposed.
The forum actor reportedly published a sample to support the breach claim. Yet, a published sample alone does not prove that Sora2U’s systems were compromised.
The sample also does not confirm that every record in the alleged database is genuine. Independent researchers would need to examine the data before confirming its source and authenticity.
Sora2U User Numbers Raise Questions
Sora2U’s own website provides additional information about the platform’s user base. According to the platform’s About page, Sora2U has more than 10,000 registered users. The alleged dataset reportedly contains information from about 7,300 unique accounts.
That number could represent a large part of the platform’s reported registered user base. However, the two figures cannot confirm that the alleged breach affected Sora2U.
The platform’s current user count may not match the period covered by the alleged dataset. The leaked database could also contain older records from a different period.
For that reason, the figures should not be treated as proof of a successful attack. Sora2U’s privacy policy also explains the types of information the platform handles. The policy indicates that the service may collect email addresses, usernames, and account-related information.
Those details appear similar to some of the information listed in the alleged database. That similarity does not prove that the records came from Sora2U. It only shows that some of the alleged fields match information the platform may handle. Sora2U’s terms of service also describe the platform as an independent community service.
The terms further state that Sora2U has no connection with OpenAI. This point matters because the name Sora2U could confuse some users with OpenAI’s official Sora service. The alleged incident therefore should not be treated as a breach of OpenAI or its Sora platform. No information provided in the claim connects the alleged database to OpenAI.
The available information only links the alleged dataset to Sora2U. At the time of writing, no credible cybersecurity publication has independently confirmed the reported breach.
No major news organization has also confirmed that the alleged database came from Sora2U. Sora2U has not publicly confirmed that its systems suffered a security incident either. The lack of confirmation leaves several important questions unanswered.
Those questions include when the alleged breach happened and how attackers supposedly accessed the data. It also remains unclear whether all 7,300 records are authentic.The source of the alleged database also requires further verification.
Users Should Watch for Possible Account Risks
The alleged leak highlights the risks that can come from exposed account and profile information. A database does not need to contain plain passwords to create security concerns. Email addresses, names, usernames, and profile information can still help attackers target users. Attackers could potentially use those details to create convincing phishing messages.
They could also attempt to trick users into revealing passwords or other private information. Password reuse could create another problem if any exposed hashes are later cracked. Users who reuse passwords across several services should consider changing those passwords. They should also avoid using the same password for multiple accounts. Multifactor authentication can provide another layer of protection when a service supports it.
Users should also be careful with unexpected emails linked to their Sora2U accounts. They should avoid clicking unknown links or sharing account information with untrusted contacts. Users can also check their accounts for unusual activity or unexpected changes.
However, these steps do not confirm that any Sora2U user has suffered an account takeover. They simply provide basic precautions while the breach claim remains under investigation. The alleged Sora2U database leak remains unverified at this time.
The publication of a sample does not independently prove that Sora2U suffered a breach. Further evidence will be needed to confirm the database’s source and authenticity. An official response from Sora2U could also provide more information about the reported incident.
Until then, users should treat the claim carefully and avoid assuming that every leaked record is genuine. The available information does not establish when the alleged breach occurred. It also does not confirm how the alleged attackers obtained the database. For now, the incident remains an unconfirmed claim involving an alleged dataset of about 7,300 accounts.