All breaches
Duolingo data breach2.7M accounts compromised on 2023-01-24
Verified
Duolingo (duolingo.com) was the source of a data breach dated 2023-01-24, exposing 2,676,696 accounts. The details below are mirrored from Have I Been Pwned and reflect the source's account of the incident at the time of publication.
Incident Report
| Target Organization | Duolingo |
|---|---|
| Source Name | Duolingo |
| Domain | duolingo.com |
| Breach Date | 2023-01-24 |
| Added to HIBP | 2023-08-23 |
| Accounts Compromised | 2,676,696(2.7M) |
| Data Exposed | Email addressesNamesSpoken languagesUsernames |
| Status | Verified by HIBP |
Description
In August 2023, 2.6M records of data scraped from Duolingo were broadly distributed on a popular hacking forum. Obtained by enumerating a vulnerable API, the data had earlier appeared for sale in January 2023 and contained email addresses, names, the languages being learned, XP (experience points), and other data related to learning progress on Duolingo. Whilst some of the data attributes are intentionally public, the ability to map private email addresses to them presents an ongoing risk to user privacy.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

