Silvi AI Allegedly Breached Through IDOR Flaw, Exposing 16,000 User Records

A threat actor claims an IDOR vulnerability in Silvi AI exposed more than 16,000 user records, including email addresses, names, and subscription information.
Screenshot of a forum post alleging a breach of Silvi AI through an IDOR vulnerability, claiming 16,483 user records containing names and email addresses were exposed.
Forum post claiming an IDOR vulnerability in Silvi AI exposed 16,483 user records and describing the alleged attack method.

A threat actor has claimed to have exploited an Insecure Direct Object Reference (IDOR) vulnerability in AI research platform Silvi AI, allegedly exposing more than 16,000 user records. The claims have not been independently verified, although the actor published technical details describing the purported attack.

According to the forum post, the vulnerability allowed authenticated users to retrieve other users’ profile information by iterating through sequential account IDs. The actor claims to have extracted data belonging to 16,483 users after creating a standard account through the platform’s public registration endpoint.

IDOR vulnerability allegedly enabled user enumeration

Silvi AI is a Denmark-based platform that helps researchers conduct AI-assisted literature reviews and academic research.

The threat actor alleges the issue stemmed from an API endpoint that returned user information based solely on a supplied numeric ID, without validating whether the authenticated user was authorized to access that record. According to the post, the actor created a new account, obtained a JSON Web Token (JWT), and then queried user IDs sequentially until approximately 16,483 records had been retrieved.

If accurate, the described behavior is consistent with an IDOR vulnerability, a common access control flaw that can expose data when object-level authorization checks are missing.

Claimed data includes user identities

The actor claims the exported records contain email addresses, first and last names, internal user IDs, organization identifiers, subscription status, and profile image locations where available.

BreachNews reviewed the sample published alongside the claim, which appears consistent with the fields described in the post. However, the publication of sample records alone is insufficient to independently verify the scope or authenticity of the alleged breach.

Latest AI platform targeted

The alleged compromise is the latest in a series of claims involving AI-focused services. Earlier this week, BreachNews reported on another alleged breach attributed to the same threat actor involving Darsa AI, where source code, credentials, and internal files were reportedly exposed. Read our coverage of the Darsa AI incident here.

At the time of publication, Silvi AI had not issued any public statement regarding the alleged incident. BreachNews will update this article if the company confirms the breach or additional evidence becomes available.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site