Sora2U Database Allegedly Leaked, Exposing 7,300 User Records

A threat actor claims to have leaked Sora2U's user database, alleging the exposure of approximately 7,300 records containing account and profile information.
Screenshot of a cybercrime forum post claiming to leak Sora2U.com’s database, alleging the exposure of approximately 7,300 user records and listing the types of account data included, with the purported data sample blurred.
A threat actor claims to have leaked Sora2U’s database, alleging the exposure of approximately 7,300 user records.

A threat actor has allegedly leaked the database of Sora2U, an AI-powered video generation platform, claiming the breach exposed approximately 7,300 user records. The post includes a downloadable archive and a sample of the purported data, although the claims have not been independently verified by BreachNews.

The database was published on a cybercrime forum on July 20, with the threat actor claiming responsibility for the alleged breach and stating the incident occurred earlier this month.

AI platform allegedly targeted

Sora2U is an AI video generation platform that allows users to create videos using artificial intelligence. The service offers user accounts with profile management, referral functionality, and personalized content generation.

Database allegedly contains account information

According to the forum post, the leaked database allegedly contains the following information:

  • Email addresses
  • Email verification status
  • Password hashes
  • Names
  • Usernames
  • Avatar URLs
  • Profile biographies
  • Referral codes
  • Account creation timestamps
  • Account update timestamps

A sample accompanying the post appears to contain user records with a mixture of populated and empty profile fields. Some accounts appear to use bcrypt password hashes, while others appear to rely on external authentication providers, resulting in blank password fields. If authentic, the exposed information could increase the risk of phishing, account takeover attempts, and credential stuffing for users who have reused passwords elsewhere.

Latest disclosure from the same threat actor

The alleged Sora2U leak was published by the same threat actor who earlier today claimed responsibility for an alleged breach of OrangeHousing. While the actor has previously been linked to both confirmed and unconfirmed disclosures, the Sora2U claims should still be treated as unverified until independently confirmed.

Sora2U yet to acknowledge alleged breach

Sora2U had not issued any public statement regarding the alleged breach at time of publication. BreachNews will update this article if the company responds or provides additional information about the alleged incident.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site
INTEL.BREACHNEWS.COM

Live Cyber
Threat Map

Explore live cyber activity, recent breach reports, KEV alerts, and public threat feeds from a single interactive dashboard.

Launch Threat Map