Dante AI Reportedly Breached With 73,547 User Accounts Claimed Exposed

A threat actor claims Dante AI was breached, alleging the exposure of 73,547 user accounts and millions of analytics events tied to platform activity.
Screenshot of a cybercrime forum post alleging a breach of Dante AI, claiming 73,547 user accounts, 2.9 million records, and analytics data were exposed, with a list of the purported data fields and a download link.
Forum post in which a threat actor claims to have breached Dante AI, alleging the exposure of 73,547 user accounts and approximately 2.9 million analytics records containing user identifiers, device metadata, and activity data.

A threat actor claims to have breached Dante AI, an AI chatbot platform that enables organizations to build custom chatbots for customer support, lead generation, and website integrations. According to the forum post, the alleged breach exposed data associated with 73,547 users alongside approximately 2.9 million analytics records. BreachNews reviewed samples from the archive but has not independently verified that the data originated from Dante AI.

The leaked archive consists of two JSON Lines datasets labeled DANTEAI_PII.json and DANTEAI_EVENTS.json, which together contain roughly 2.9 million records. The files are being distributed as a free download on a cybercrime forum.

Analytics data tied to user accounts

Analysis of the leaked files indicates the records are structured as analytics events rather than a traditional customer database export. Individual records contain user identifiers alongside event telemetry, device metadata, geographic information, and application activity.

The reviewed data includes email addresses, IP addresses, city, region and country information, device IDs, session identifiers, UUIDs, browser and operating system details, platform information, event timestamps, and authentication-related metadata. Some records also contain advertising attribution identifiers and marketing parameters associated with user sessions.

Rather than simple login records, many events capture activity performed within the platform, including page visits and chatbot interactions.

Platform activity and AI model usage visible

BreachNews observed event records referencing chatbot identifiers, page URLs, and language models including Claude 3.5 Sonnet. Other records reference customer-facing pages such as chatbot settings and application dashboards, indicating the dataset captures user activity within the platform rather than only account registration data.

The archive also contains marketing attribution metadata, including UTM parameters and advertising identifiers from Google, Facebook, LinkedIn, Microsoft, and TikTok, allowing activity to be correlated across user sessions.

Part of an ongoing series of alleged SaaS breaches

The same threat actor has recently published multiple alleged datasets involving SaaS platforms, AI services, educational platforms, and analytics exports. BreachNews previously reported similar claims targeting King of the Curve, Mailshake, and Ling App, where customer information, account metadata, and analytics telemetry were likewise reportedly exposed.

Dante AI had not issued any public statement regarding the alleged breach at the time of publication.

If authentic, the dataset could expose identifiable customer activity, device information, marketing attribution data, and platform usage patterns tied to individual accounts. BreachNews will update this article if Dante AI confirms or disputes the alleged incident.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site