2.6 million user accounts leaked in Duolingo data breach

An exposed application programming interface (API) at Duolingo allowed threat actors to scrape the personal information of 2.6 million users, including email addresses, phone numbers, and usernames. The data was then leaked on an underground hacking forum.

Duolingo said that its systems were not compromised in the breach, but that the data was scraped from publicly available profile information. However, researchers have found that the API also allowed threat actors to obtain private user information, such as email addresses.

Duolingo has since fixed the exposed API. While Max Gannon, a Senior Cyber Threat Intelligence Analyst, suggests that while the data may seem low in value, it could be leveraged for highly targeted attacks.

On March 2, a researcher named Ivano Somaini tweeted about using Duolingo’s API to check if an email is linked to a Duolingo account. This API lets users verify if a username or email is associated with a Duolingo account. It’s still accessible online, despite being reported for misuse in January.

It shows how often the user uses Duolingo, a URL for the profile picture, learning languages, XP points, and crowns as well as l courses, progress, and XP points. It goes ahead to indicate if the profile is linked to Facebook or Google coupled with the Duolingo’s user ID, account’s username and phone number.

The sources for this piece include an article in CPOMAGAZINE.

Top Stories

Related Articles

May 31, 2025 A coordinated supply chain attack has compromised between 500 and 1,000 e-commerce websites by exploiting vulnerabilities in 21 more...

May 31, 2025 A widely used open-source Go library, easyjson, used in healthcare, finance and even defence has come under scrutiny more...

May 31, 2025 (EDITORIAL) A messaging tool used by Trump administration officials to archive encrypted Signal messages has been hacked — more...

April 22, 2025 Anthropic, a leading artificial intelligence company, anticipates that AI-powered virtual employees could begin operating within corporate networks as more...

Jim Love

Jim Is and author and pud cast host with over 40 years in technology.