Israeli cybersecurity startup RedAccess found 380,000 apps built with Lovable, Replit, Base44, and Netlify publicly accessible with virtually no security. About 5,000 leaked medical records, financial data, and customer chatbot logs due to default-public privacy settings. Phishing sites impersonating Bank of America, FedEx, and McDonald's were also found built with Lovable.