Breach report
EducationDuolingo
Scraped data of 2.6 million Duolingo users released on hacking forum
Data scraped from about 2.6 million Duolingo accounts through an exposed API, including email addresses that are not publicly visible, was released on a hacking forum in August 2023 after earlier being sold.
Reported by BleepingComputer
Records exposed
2.6M
About 2.6 million users
Scale vs. largest on file
- When
- 2023
- How they got in
- API scraping (exposed endpoint matching email addresses to profiles)
- Sector
- Education
In January 2023, a seller on the Breached hacking forum offered a dataset of about 2.6 million Duolingo user records for $1,500. The data had been scraped from the language-learning app using an exposed application programming interface that allowed anyone to submit an email address and receive the matching user's profile. In August 2023, the dataset was released on a new version of the forum for a nominal fee in site credits, making it broadly accessible.
The records combined information that Duolingo displays publicly, such as usernames, real names, the languages users study and their experience points, with email addresses that are not public. That combination is what made the data valuable. The scrapers had fed lists of email addresses, often taken from earlier breaches, into the API to find which ones belonged to Duolingo accounts, then saved the returned profile details. Researchers noted that the API remained openly accessible for months after the initial sale, and that others were demonstrating how to use it.
Duolingo said the information had been obtained through scraping of public profile data, that there had been no breach of its systems, and that it was investigating whether further steps were needed. Critics pointed out that email addresses are not public on Duolingo, meaning the scraping had exposed non-public information. Breach-notification service Have I Been Pwned later added the records so users could check whether they were included. No regulatory action was announced.
The incident mirrored earlier scraping episodes at Facebook and Twitter, where features intended to help people find friends were abused to connect email addresses or phone numbers with profiles on a massive scale. Although no passwords or payment information were involved, the data gave criminals a ready-made list of confirmed Duolingo users and their real names, well suited to phishing campaigns impersonating the popular app.
The Duolingo case illustrates why companies increasingly treat scraping as a data security problem rather than a mere nuisance. Enumeration endpoints that confirm whether an email address is registered can leak information users reasonably expect to stay private, particularly when combined with public profile data. For developers, the lesson is to authenticate and rate-limit lookup APIs; for users, it is to be wary of unexpected messages that reference accounts they hold.