Skip to content

Silvi AI User Data Allegedly Exposed via API Flaw, 16,483 Researcher Records Published

Breach Report Denmark flagDenmark AI / Research Tools Point-Gated Download

Silvi AI User Data Allegedly Exposed via API Flaw, 16,483 Researcher Records Published

A forum user posting as NightBroker has published what they describe as the user database of Silvi AI, a Danish service that automates academic literature reviews. The release claims 16,483 records containing names, email addresses, organisation identifiers, subscription status, and profile image references. The actor states the data was obtained not through a compromise of infrastructure but by abusing the platform's public API, describing an unvalidated self-registration endpoint followed by sequential enumeration of user records using the resulting token. If accurate, that describes a broken object-level authorisation flaw requiring no specialist tooling. The claim is unverified.

Records16,483
VectorAPI authorisation
PriceFree
ActorNightBroker

Post details

TargetSilvi AI
CountryDenmark flagDenmark
SectorAI / Academic research tools
ListingPoints to unlock
Records16,483 users
MethodClaimed API abuse, not intrusion
Observed
ActorNightBroker

!Allegedly included

  • Email addresses
  • First names
  • Last names
  • User identifiers
  • Organisation identifiers
  • Subscription status
  • Profile image references

Screenshot

Potential impact

The data itself is limited: names, emails, and subscription status, with no passwords, payment details, or research content. The exposure matters less for what was taken than for how easily it was reportedly taken. Broken object-level authorisation is the most common API weakness in the field, and a flaw of this kind remains exploitable by anyone until it is fixed, meaning the published set may not be the last. The user base appears to be academics and institutional researchers, whose addresses are useful for targeted phishing against universities. As a Danish operator, Silvi AI falls under GDPR notification obligations.

iStatus

Unverified

The post includes a record sample and a detailed account of the method, which Dark Web Informer is not reproducing as the weakness may remain live. The account is established with moderate standing. The described technique is consistent with the fields obtained, which lends the account some internal coherence, but nothing has been independently corroborated. The claim is unverified and Silvi AI has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest