A threat actor claims to have breached Dante AI, an AI chatbot platform that enables organizations to build custom chatbots for customer support, lead generation, and website integrations. According to the forum post, the alleged breach exposed data associated with 73,547 users alongside approximately 2.9 million analytics records. BreachNews reviewed samples from the archive but has not independently verified that the data originated from Dante AI.
The leaked archive consists of two JSON Lines datasets labeled DANTEAI_PII.json and DANTEAI_EVENTS.json, which together contain roughly 2.9 million records. The files are being distributed as a free download on a cybercrime forum.
Analytics data tied to user accounts
Analysis of the leaked files indicates the records are structured as analytics events rather than a traditional customer database export. Individual records contain user identifiers alongside event telemetry, device metadata, geographic information, and application activity.
The reviewed data includes email addresses, IP addresses, city, region and country information, device IDs, session identifiers, UUIDs, browser and operating system details, platform information, event timestamps, and authentication-related metadata. Some records also contain advertising attribution identifiers and marketing parameters associated with user sessions.
Rather than simple login records, many events capture activity performed within the platform, including page visits and chatbot interactions.
Platform activity and AI model usage visible
BreachNews observed event records referencing chatbot identifiers, page URLs, and language models including Claude 3.5 Sonnet. Other records reference customer-facing pages such as chatbot settings and application dashboards, indicating the dataset captures user activity within the platform rather than only account registration data.
The archive also contains marketing attribution metadata, including UTM parameters and advertising identifiers from Google, Facebook, LinkedIn, Microsoft, and TikTok, allowing activity to be correlated across user sessions.
Part of an ongoing series of alleged SaaS breaches
The same threat actor has recently published multiple alleged datasets involving SaaS platforms, AI services, educational platforms, and analytics exports. BreachNews previously reported similar claims targeting King of the Curve, Mailshake, and Ling App, where customer information, account metadata, and analytics telemetry were likewise reportedly exposed.
Dante AI had not issued any public statement regarding the alleged breach at the time of publication.
If authentic, the dataset could expose identifiable customer activity, device information, marketing attribution data, and platform usage patterns tied to individual accounts. BreachNews will update this article if Dante AI confirms or disputes the alleged incident.












