Duolingo Data Breach (2023): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Duolingo Data Breach (2023) (reported January 24, 2023) exposed Email addresses, Names, Spoken languages and Usernames belonging to roughly 2.7M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Language-learning platforms sit among the consumer apps that hold large volumes of account and progress data, and they have become regular targets for scraping and bulk redistribution of user records. In that landscape, a 2023 incident involving Duolingo stands out for the scale of records later circulated and for the method used to obtain them.
Public reporting ties the episode to roughly 2.7 million people affected. Records associated with the platform were offered for sale in January 2023 and later appeared in bulk on a popular hacking forum. The material included email addresses mapped to names, usernames, languages, and learning-progress details—creating a lasting privacy concern even where some profile attributes were already visible by design.
Inside the incident
According to the reported summary, data scraped from Duolingo was obtained by enumerating a vulnerable API. The records first appeared for sale in January 2023. In August 2023, approximately 2.6 million of those records were broadly distributed on a popular hacking forum. Reporting associated with the incident lists about 2.7 million people affected and dates the public report to 24 January 2023.
The circulated data set is described as containing email addresses, names, the languages being learned, XP (experience points), and other data related to learning progress. Usernames and spoken languages are also named among the exposed types. No further public detail is given on the precise technical path beyond API enumeration, on any internal detection timeline, or on whether the company confirmed a full account of every field present. The summary notes that while some attributes are intentionally public on the service, the ability to map private email addresses to them presents an ongoing risk to user privacy.
How a breach like this happens
Incidents of this type commonly begin when an interface meant for legitimate app or partner use can be queried in bulk without adequate rate limits, authentication checks, or authorisation controls. An attacker who discovers that pattern can systematically request profile or progress records, assemble a large corpus, and then offer or release it. The initial collection may not involve malware on user devices or a direct break-in to a core database; instead it exploits how the service answers repeated, automated requests.
Once compiled, such data sets often surface first in private sales channels and later on open forums. Redistribution does not require the original collector to remain involved. Because email addresses serve as stable identifiers across many services, the combination of contact details with otherwise semi-public profile fields increases the usefulness of the set for spam, phishing, or account-correlation attempts long after the first listing. No specific threat group is attributed in the available facts for this incident, and none should be assumed.
About Duolingo
Duolingo is a widely used language-learning platform that offers free and paid courses through web and mobile applications. Services of this kind typically maintain user accounts tied to email addresses, display names or usernames, selected languages, and metrics that track lessons completed, streaks, and experience points. They may also store preferences, device or session metadata, and payment information for subscribers, though the exact inventory varies by product and is not fully detailed in the breach facts.
A large user base means that even a partial scrape can affect millions of people. Because learners often use the same email address for other accounts, exposure on a language app can have consequences beyond the original service. The combination of identity and activity data also makes the platform a consequential target for anyone seeking to build profiles of individuals’ interests or contact points.
The information in question
The facts name the following data types as exposed: email addresses, names, spoken languages, and usernames. The reported summary additionally describes languages being learned, XP, and other learning-progress data. It states that some of these attributes are intentionally public on the platform, while the linkage to private email addresses is the core privacy issue.
Exact contents of every record, any additional fields that may have been present, and confirmation of whether every affected person saw the same set of attributes remain limited in public reporting. Organisations in this sector commonly hold account identifiers, progress statistics, and contact details; readers should treat only the named categories as confirmed for this incident and regard anything further as unconfirmed.
Why it matters
For affected individuals, the practical risks centre on unwanted contact and social-engineering attempts. An email address paired with a real name and evidence of language study can make phishing messages appear more plausible. Usernames and progress details can aid correlation with other online profiles. Even when some information was already visible, bulk availability lowers the effort required for misuse and extends the window during which the data can be resold or reused.
For the organisation, the episode underscores the lasting exposure that follows API-based collection and public redistribution. Trust, support burden, and the need to harden interfaces are typical consequences. The facts do not establish negligence as a finding; they simply record that a vulnerable API was enumerated and that the resulting records circulated.
If your data was in this breach
If you used Duolingo with an email address that may appear in the circulated sets, consider the following practical steps:
- Change your Duolingo password and enable any available multi-factor authentication.
- Treat unsolicited messages that reference language learning or your username with caution; verify them through the official app or site rather than links in email.
- Monitor the inbox tied to the account for phishing or credential-reset attempts and avoid reusing the same password on other services.
- Review account recovery options and remove outdated secondary emails or phone numbers you no longer control.
- Run a free exposure scan of your email address to check whether it has surfaced in known breach data sets.
Public detail on individual notification and on the full technical scope remains limited. Staying alert to unusual account activity and reducing password reuse remain the most direct protections available to users.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
GLAMIRA Data Breach (2023)Welhof Data Breach (2023)Zadig & Voltaire Data Breach (2023)Blooms Today Data Breach (2023)Latest breaches
Read GalaxyWarden’s full analysis of the Duolingo Data Breach (2023) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.