[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbrcl0az05t04":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":36,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda4882519a","duolingo","Duolingo Data Breach","duolingo.com","2023-01-24T00:00:00.000Z","2023-08-23T04:31:08.000Z","2026-07-09T21:58:35.278Z","2026-07-18T23:49:55.471Z","Config exposure","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fdata-of-26-million-duolingo-users-leaked-on-hacking-forum\u002F",[15,17,18,19],"https:\u002F\u002Fwww.twingate.com\u002Fblog\u002Ftips\u002Fduolingo-data-breach","https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Femail-addresses-names-and-phone-numbers-of-2-6-million-duolingo-users-available-for-2-on-hacking-forum","https:\u002F\u002Fwww.infosecurity-magazine.com\u002Fnews\u002Fdata-26m-duolingo-users-leaked\u002F",2676696,"known",null,"unknown","Critical",[26,27,28,29,30],"Email addresses","Names","Usernames","Spoken languages","Learning progress","\u003Cp>The Duolingo data breach is a mass data extraction incident that became visible when user data on the language learning platform was put up for sale in January 2023 and more widely released in August 2023. The record contains 2,676,696 unique accounts. Verified data fields include email addresses, names, usernames, languages learned or spoken, and some information regarding learning progress. This incident does not involve a leak of passwords, payment cards, or course content; the main risk is that private email addresses could be matched with publicly visible profile fields.\u003C\u002Fp>\n\u003Cp>It would not be accurate to describe the Duolingo incident in the traditional sense as a direct system takeover. It appears that publicly or semi-publicly accessible profile fields could be collected on a large scale through weak account query logic. Some profile information may have been left visible by the user; however, matching a private email address with these profile fields increases privacy risk. Fields such as language preference, username, name, and learning progress could be used in phishing, fake account alerts, or personalized training offer messages. Therefore, the Duolingo data breach should be considered more as a profile matching and targeted fraud risk rather than a password change issue.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Verified data types include email addresses, names, usernames, languages spoken or learned, and some information related to learning progress. When the email address, username, and name are together, a person's profiles on different platforms can be linked. Language preferences can help an attacker understand in which language to send a message and which learning goal to associate the message with. Fields such as learning progress or scores can also reinforce the impression that the account truly belongs to a Duolingo user.\u003C\u002Fp>\n\u003Cp>In this incident, password information is not a verified data field. Therefore, the user should not be given the impression that their password has been leaked. The risk is less about the account being directly compromised and more about the email address being matched with the Duolingo profile and this information being used in targeted messages. For example, messages such as language course, membership renewal, account verification, level loss, or learning streak warnings can become more convincing. Users should not consider the inclusion of their username or the language they are learning in a message as proof of legitimacy.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified incident date is tracked as January 2023; the dataset circulated more widely in August 2023. The number of affected records is kept as 2,676,696. Some sources may mention approximately 2.6 million or 2.7 million users; these expressions are rounded representations of the same incident. The number used in this record is the count of unique records used in the query. Data fields are limited to language learning profile and email matching.\u003C\u002Fp>\n\u003Cp>The scope should not be expanded. In this record, password, payment card, bank account, official ID, phone number, physical address, private lesson content, or private message are not verified data classes. Although some profile fields may be public, bulk matching with a private email address increases the privacy impact. Therefore, the record should not be seen as completely trivial like a public profile list. The correct assessment should be made based on the risk arising from combining email and profile data, rather than direct account takeover.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group consists of people who use their real name, recognizable username, or primary email address on Duolingo. People who use the same username on social networks, educational platforms, or work profiles are easier to associate. Language preference and learning progress can provide clues about a user's personal goals or country interests. Although this information alone is not considered highly sensitive data, when combined with email and name, it increases the perceived accuracy of targeted messages.\u003C\u002Fp>\n\u003Cp>Students, teachers, those preparing for exams, people learning a language for migration or work purposes, and those using their main email for educational accounts may become more visible. Attackers can combine these areas with fake exam, certificate, subscription, gift, account verification, or learning series alerts. Since there is no password leak, the risk of direct account takeover is limited; however, the risk of social engineering, spam, and profile matching is real.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Using a strong and unique password on your Duolingo account is a good security step; however, in this case, since it has not been confirmed that the password was leaked, the main priority is to distinguish suspicious messages. Attention should be paid to links in account verification, membership, level loss, learning streak, certificate, or campaign messages coming under the name of Duolingo. Even if your name, username, or the language you are learning is correct in the message, this information could have been taken from a data set. If an action is required, it should be carried out by accessing the service directly through the official address.\u003C\u002Fp>\n\u003Cp>In your profile, visible areas should be reviewed to reduce the association of your real name, public username, and primary email. If the primary email address is used in too many training sessions, campaigns, or social accounts, separate email addresses may be preferred. Passwords, payment information, or one-time codes should not be shared in unexpected emails and messages. Two-factor authentication should be enabled on the email account, and suspicious sessions should be checked. In this case, just because there is no password leak does not mean all risks should be ignored.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>In the long term, users should regularly check which profile fields are public on educational and social platforms. When real name, username, language goals, profile photo, and email link come together, a person can easily become recognizable. Instead of using the main email address for every service, assigning separate addresses for different purposes reduces the impact of such mass data harvesting incidents. A password manager and two-factor authentication should still be maintained for overall account security.\u003C\u002Fp>\n\u003Cp>From the perspective of platform operators, the Duolingo incident shows that even data that appears to be public can pose a privacy risk when matched with private email addresses. Account query processes should be limited against abuse, bulk data extraction behaviors should be detected early, and the connection between private fields and profile fields should not be unnecessarily exposed. Educational platforms should not treat fields such as users' learning goals and language preferences as mere basic profile information.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If you see a match in this record, your account may be among the 2,676,696 records associated with the Duolingo data breach. A match does not mean that your password or payment information has been leaked. The verified fields include email, name, username, spoken or learned languages, and some information about learning progress. The first step is to be more cautious with Duolingo-themed messages sent to this email address and not to click on links directly.\u003C\u002Fp>\n\u003Cp>Check the information displayed on your Duolingo profile, minimize the appearance of your primary email address in unnecessary places, and keep additional verification on your email account enabled. If you use the same username on other platforms, consider the risk of profile matching. The correct approach to a Duolingo data breach is not to exaggerate the event as a password leak, but to reduce the targeted messaging and privacy risks arising from the matching of your profile and learning data with your email address.\u003C\u002Fp>","","Duolingo Data Breach (2.7 Million Reported Records)","Duolingo Data Breach. 2.7 Million reported records were reported. Reported data: Email addresses, Names, Usernames. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fduolingo_com.webp",false,{"name":38,"sector":39,"country":40,"website":9,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":22},"Duolingo","Education","United States"]