Categories: Tech & Ai

Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the Web


Sears department stores have largely disappeared across the United States, but the brand and its appliance repair service are still in business, complete with a modern twist: an AI chatbot and phone assistant named Samantha. As the historic retailer steps into the future, though, new research shows that conversations people had with the chatbot were publicly exposed online.

Since Sears is still a trusted name but largely out of the public eye, security researcher Jeremiah Fowler was surprised and alarmed last month when he found three publicly exposed databases containing massive troves of chat logs, audio files, and text transcriptions of audio that contained personal details about Sears Home Services customers. The Home Services division claims to be the US’s “largest appliance repair service provider” and reports that it performs more than seven million repairs each year.

The exposed Sears databases uncovered by Fowler, which have since been secured, contained 3.7 million chat logs, plus 1.4 million audio files and plain text transcripts from 2024 to this year. Fowler found that one CSV file about the incident contained 54,359 complete chat logs. Conversations Fowler saw included the chatbot introducing itself as “Samantha, an AI virtual voice agent for Sears Home Services,” with the logs also including the name of the company’s AI technology “kAIros.” The cache of data contained chats in both English and Spanish and included personal information about Sears customers, such as names, phone numbers, home addresses, appliances owned, and information on delivery appointments and repairs.

“The thing to remember is that it is real data of real people,” says Fowler, a researcher with Black Hills Information Security. While companies may be able to save money deploying AI, he emphasizes that it is crucial they “don’t take any shortcuts when it comes to protecting that data, securing that data. At the bare minimum, these files should have been password protected and encrypted.”

After finding the publicly accessible databases at the start of February, Fowler emailed staff at Transformco, the company that owns Sears and Sears Home Services, and the databases were quickly secured, he says. It is unclear how long the databases were exposed online and whether anyone other than Fowler accessed them during that time. Transformco did not respond to multiple requests for comment from WIRED about the information being available to anyone on the web.

Fowler says that when he disclosed the finding to Transformco, he received a reply from someone who claimed that they were connecting him directly with a Samantha AI Chatbot manager. He says that individual never replied to him, though, even after a follow -up message.

Any exposed customer data is problematic, but Fowler was particularly concerned about the Sears data for two reasons. First, such information would be extremely useful in phishing attacks, because it includes details about customers’ contact information and home lives, including their appliances, which could be exploited for warranty scams and other targeting.

The second shock came from the fact that a surprising number of the audio calls captured hours of ambient audio after customers apparently thought a call had ended. Some of the recordings were up to four hours long. It is unclear why customers left the calls running once they were done speaking to the Sears AI agent, but these extended recording sessions may have captured private conversations and sensitive details that Sears customers thought they were discussing privately as they went about their days. “You could hear the TV playing, you could hear people having conversations, and this recorded all of it,” Fowler says.



Source link

Abigail Avery

Share
Published by
Abigail Avery

Recent Posts

Bitcoin Price Analysis: BTC Just Broke $81,000 and Triggered a Short Squeeze — Is $83,400 the Next Target?

Bitcoin price pushed above $81,000 on May 5, a 1.47% gain in 24 hours that…

16 minutes ago

Pornhub Restores Access for UK Adults Who Use Apple’s Age Verification

Three months after Pornhub blocked access to new users in the United Kingdom, the adult…

25 minutes ago

Crypto ETPs log five straight weeks of inflows, topping $4B

Crypto asset ETPs just notched a fifth straight week of inflows, lifting five-week net flows…

1 hour ago

Threads finally brings messaging to the web

Threads is rolling out messaging on the web, bringing one-on-one and group chats to desktop,…

1 hour ago

A16z Crypto Unveils $2.2 Billion Fund to Build the ‘Next Wave’ of Financial Innovation

Key Takeaways: A16z Crypto launched its $2.2B Crypto Fund 5 to help startups build the…

1 hour ago

Trump rejects Iran’s peace proposal, maintains economic pressure

## Market Snapshot WTI Crude Oil Prices for May 2026 are currently observing potential decreases,…

2 hours ago