Skip to main content
WhatTermsWhatTerms
← Back to Duolingo

Breach exposure

Public breaches involving Duolingo

Cross-matched against the WhatTerms breach catalog. Each entry links the breach disclosure, names the data classes confirmed exposed, and matches each class to a concrete recovery action — not just “your email was leaked”.

Recovery actions

Sorted by severity. Each action maps to one or more data classes confirmed exposed across the breaches below.

  • Switch this service to a per-service email alias and treat the leaked address as compromised.

    Medium

    Exposed emails feed phishing campaigns and credential-stuffing lists.

  • Audit accounts where you reuse this handle; assume it can be cross-correlated.

    Medium

    Handle reuse links pseudonymous accounts back to your real identity.

Duolingo

Disclosed 2023-08-23 · 2.6M accounts

API scrape mapped public usernames to private email addresses.

Data classes exposed

  • Email address
  • Username / handle

Source: Disclosure on hacker forum; confirmed by Bleeping Computer. Read disclosure ↗