
Language learning platform DuoLingo, which produces learning apps and offers 98 courses across nearly 40 distinct languages, is investigating a post on a hacking forum offering information on 2.6 million customer accounts for $1,500.
No data breach or hack has taken place, according to a company spokesperson, but the company is aware of the post, which was published on Tuesday morning, offering emails, phone numbers, courses taken, and other details about how users of the platform use the platform. According to the spokesperson, the company is looking into whether any additional steps are required to protect its students.
In a hacker forum, where the DuoLingo database (scraped) has been advertised for sale, the hacker provided a sample of data from 1,000 accounts in the post and claimed to have obtained the data by scraping an exposed application programming interface (API). The user claimed that the data in question contains 2.6 million account entries.
Notably, many of the biggest tech companies are plagued by the problem of social media sites and platforms like DuoLingo being scraped. Today, a wide variety of tools enable users to scrape APIs and extract massive amounts of data from websites. According to Human Security, using bots by cybercriminals led to a 240% annual increase in web scraping in 2022.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543