Cyber Security News

Over 2.6 Million DuoLingo Users’ Info Exposed in a Hacker’s Forum

The popular language learning platform has come under scrutiny as a post on a hacker’s forum offers access to information from 2.6 million customer accounts for a mere $1,500. 

Duolingo is an American educational technology company that produces learning apps and provides language certification.

The hacking forum post, created on a Tuesday morning, caught DuoLingo’s attention as it offered sensitive customer account details, including emails, phone numbers, courses taken, and other usage-related information for a price.

A spokesperson for the company has stated to Record that these records were amassed through data scraping public profile information, emphasizing that no data breach or hack has occurred. 

“No data breach or hack has occurred. We take data privacy and security seriously and are continuing to investigate this matter to determine if there’s any further action needed to protect our learners.”

DuoLingo’s team is actively investigating the matter to assess the need for further protective actions to ensure their users’ safety.

The Origins of Data Scraping

Data scraping, or web scraping involves automated data extraction from websites and online platforms. 

While scraping of public information is common, it becomes problematic when sensitive and private data is compromised. 

In this case, the hacker claimed to have sourced the information by exploiting an exposed Application Programming Interface (API).

The hacker also showcased their illicit achievement by sharing a sample dataset from 1,000 accounts.

DuoLingo Users Data Exposed

The Widespread Nature of Web Scraping

The DuoLingo incident highlights a pervasive problem faced by tech companies worldwide. 

Numerous tools and techniques are available to scrape APIs, allowing individuals to amass vast amounts of data from websites. 

Often, this data is publicly accessible, but there are instances where it becomes accessible through links to other sites, inadvertently putting sensitive information at risk.

Tech giants are also vulnerable to web scraping. Meta (previously Facebook) filed a lawsuit against a surveillance service for generating fake accounts on Instagram and Facebook to scrape user data.

Similarly, in 2021, Facebook sued an individual who scraped the data of over 178 million Facebook users, exploiting the contacts import feature in its Messenger app. 

Keep informed about the latest Cyber Security News by following us on Google NewsLinkedinTwitter, and Facebook.

Sujatha

Sujatha is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under her belt in Cyber Security, she is covering Cyber Security News, technology and other news.

Recent Posts

New Chaosbot Leveraging CiscoVPN and Active Directory Passwords to Execute Network Commands

ChaosBot surfaced in late September 2025 as a sophisticated Rust-based backdoor targeting enterprise networks. Initial…

14 hours ago

Threat Actors Exploiting SonicWall SSL VPN Devices in Wild to Deploy Akira Ransomware

Threat actors have reemerged in mid-2025 leveraging previously disclosed vulnerabilities in SonicWall SSL VPN appliances…

14 hours ago

Nanoprecise partners with AccuKnox to strengthen its Zero Trust Cloud Security and Compliance Posture

Menlo Park, USA, October 10th, 2025, CyberNewsWire AccuKnox, a leader in Zero Trust Cloud Native…

15 hours ago

175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide

Socket's Threat Research Team has uncovered a sophisticated phishing campaign involving 175 malicious npm packages…

15 hours ago

RondoDox Botnet Exploits 50+ Vulnerabilities to Attack Routers, CCTV Systems and Web Servers

Since its emergence in early 2025, RondoDox has rapidly become one of the most pervasive…

16 hours ago

Microsoft Defender Incorrectly Flags SQL Server Software as End-of-life

Microsoft Defender for Endpoint is incorrectly flagging specific versions of SQL Server as having reached…

18 hours ago