2.6 million user accounts leaked in Duolingo data breach

September 1, 2023

An exposed application programming interface (API) at Duolingo allowed threat actors to scrape the personal information of 2.6 million users, including email addresses, phone numbers, and usernames. The data was then leaked on an underground hacking forum.

Duolingo said that its systems were not compromised in the breach, but that the data was scraped from publicly available profile information. However, researchers have found that the API also allowed threat actors to obtain private user information, such as email addresses.

Duolingo has since fixed the exposed API. While Max Gannon, a Senior Cyber Threat Intelligence Analyst, suggests that while the data may seem low in value, it could be leveraged for highly targeted attacks.

On March 2, a researcher named Ivano Somaini tweeted about using Duolingo’s API to check if an email is linked to a Duolingo account. This API lets users verify if a username or email is associated with a Duolingo account. It’s still accessible online, despite being reported for misuse in January.

It shows how often the user uses Duolingo, a URL for the profile picture, learning languages, XP points, and crowns as well as l courses, progress, and XP points. It goes ahead to indicate if the profile is linked to Facebook or Google coupled with the Duolingo’s user ID, account’s username and phone number.

The sources for this piece include an article in CPOMAGAZINE.

Top Stories

Related Articles

April 17, 2026 Booking.com has confirmed a data breach exposing customer booking details and contact information, prompting warnings about a more...

April 1, 2026 Anthropic has inadvertently exposed the full source code of its Claude Code tool for the second time more...

April 1, 2026 Cisco suffered a cyberattack after attackers used stolen credentials from a compromised developer tool to access its more...

March 30, 2026 Google has expanded its “Results about you” tool, allowing users to remove highly sensitive personal data, including more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn