Site navigation

Duolingo Data Scrape Used Still-Active API Vulnerability

Elizabeth Greenberg

,

duolingo data scrape
Duolingo users’ public, and even private, information has been re-released on a hacking forum. 

Duolingo data from 2.6 million users has been scraped from the language learning app, and is now for sale on a hacking forum, according to VX Underground. The exposed information, including email addresses, names, and profile pictures, can be used to conduct phishing attacks.

Information currently for sale includes users usernames and full names, which are public information, according to Duolingo, but also email addresses, which are not publicly available. The language app has around 74 million global users, making it a prime pool of victims if their data can be easily accessed.

The scraped data was first reported in January of this year, but was re-released this week on a newer version of Breached, a hacking forum, as reported by FalconFeedsio on X.

When it was first made aware of the incident, Duolingo said that as the data was public information, they were investigating if they needed any further cybersecurity precautions. This, however, did not address the fact that the emails exposed were not public information, and therefore could not be scraped from the site.

To gain access to user emails, threat actors utilised an exposed application programming interface (API), which has been circulated and known since at least March 2023.

The API attack format in this case is similar to credential stuffing – hackers can submit a Duolingo username and retrieve a JSON output revealing the user’s public information, but the same can be done by submitting an email address to find an associated Duolingo account.

Scrapers could therefore insert potentially millions of email addresses into the API to match them to Duolingo accounts, which were then used to match the private email addresses to public information.


Recommended


With an email, full name, and even a profile pictures, threat actors will be better able to conduct more pernicious phishing attacks.

According to Bleeping Computer, the API is still active, even though it has been known since the initial scrape in January.

Allowing private data to be accessed via a known vulnerability could be in violation of data protection laws, and put consumers at risk of phishing attacks.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data