Vietnam.vn - Nền tảng quảng bá Việt Nam

Data of 2.6 million Duolingo users leaked publicly

Báo Thanh niênBáo Thanh niên24/08/2023


Duolingo is the world's largest language learning website and app with over 74 million monthly users. According to Bleeping Computer, the leaked personal data of Duolingo users would allow hackers to launch targeted phishing attacks.

In January 2023, an account on a hacker forum sold data collected from 2.6 million Duolingo users for $1,500, and the forum has since been shut down.

This data includes login credentials, real names, and non-public information, including email addresses and internal information related to Duolingo's service. While Duolingo user profiles publicly display real names and login names, email addresses are anonymized.

Dữ liệu 2,6 triệu người dùng Duolingo bị phát tán công khai - Ảnh 1.

Ad sells 2.6 million Duolingo user data for $1,500

Duolingo confirmed to TheRecord that the data collected and sold was taken from public records, and that the service is investigating whether to take further precautions. However, Duolingo did not mention that email addresses were also listed in the data.

Data from 2.6 million users was released yesterday on a new version of the hacker forum for just $2.13. The data was collected using an application programming interface (API) that has been publicly shared since March 2023.

This Duolingo API allows anyone to submit a request to retrieve a user's public profile information. However, it is also possible to provide an email address to the API and confirm whether that address is associated with a Duolingo account.

BleepingComputer said the API remained publicly available even after its abuse was reported to Duolingo in January.

It's possible the hacker fed millions of email addresses — likely exposed in previous data breaches — into the API to see if they belonged to Duolingo accounts. These email addresses were then used to create a dataset containing public and non-public information.

Dữ liệu 2,6 triệu người dùng Duolingo bị phát tán công khai - Ảnh 2.

Hacker Re-Uploads Data of 2.6 Million Duolingo Users for a Very Cheap Price

Companies tend to discard collected data, as most of it is already public. However, when public data is mixed with private data such as phone numbers and email addresses, it makes the information exposed more risky and potentially violates data protection laws.

In 2021, Facebook suffered a massive data breach after its “Add Friend” API was misused to link phone numbers to the Facebook accounts of 533 million users. The Irish Data Protection Commission (DPC) fined Facebook €265 million ($275.5 million) for causing the breach. A recent bug in Twitter’s API was used to scrape public data and email addresses for millions of users, leading to an investigation by the DPC. Duolingo has yet to explain why it left the API open to everyone after abuse reports were received.



Source link

Comment (0)

No data
No data
Wild beauty on Ha Lang grass hill - Cao Bang
Vietnam Air Force practices preparing for A80
Missiles and combat vehicles 'Made in Vietnam' show off their power at A80 joint training session
Admire the million-year-old Chu Dang Ya volcano in Gia Lai
It took Vo Ha Tram 6 weeks to complete the music project praising the Fatherland.
Hanoi coffee shop is bright with red flags and yellow stars to celebrate the 80th anniversary of National Day September 2nd
Wings flying on the A80 training ground
Special pilots in the flying formation to celebrate National Day September 2
Soldiers march through the hot sun on the training ground
Watch helicopters rehearse in the sky of Hanoi in preparation for National Day September 2

Heritage

Figure

Business

No videos available

News

Political System

Destination

Product