Cyber Hacking News

2.6 million Duolingo account entries released on hacking forum

0

The scraped data of 2.6 million DuoLingo users was leaked on a hacking forum, allowing threat actors to conduct targeted phishing attacks using the exposed information.

Duolingo, one of the largest language learning sites in the world, has over 74 million monthly users worldwide.

In January 2023, a threat actor was selling the scraped data of 2.6 million DuoLingo users on the now-shutdown Breached hacking forum for $1,500.

Now, VX-Underground spotted that the scraped 2.6 million user dataset was released this week on a new version of the Breached hacking forum for 8 site credits, worth only $2.13.

This data includes a mixture of public login and real names, and non-public information, including email addresses and internal information related to the DuoLingo service.

When the data was put for sale, DuoLingo confirmed that it was scraped from public profile information and that they were investigating whether further precautions should be taken.

This data was scraped using an exposed application programming interface (API) that has been shared openly since at least March 2023, with researchers tweeting and publicly documenting how to use the API.

The API allows anyone to submit a username and retrieve JSON output containing the user’s public profile information. However, it is also possible to feed an email address into the API and confirm if it is associated with a valid DuoLingo account.

This API is still openly available to anyone on the web, even after its abuse was reported to DuoLingo in January.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Seiko breached by BlackCat ransomware gang

Previous article

Over 3,000 Openfire servers vulnerable to takeover attacks

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *