The Duolingo data breach affected a significant number of users, exposing personal information that can be used for identity theft, phishing, and fraud. If you've ever had an account or relationship with Duolingo, it's worth checking whether your data was involved.
What Happened
In early 2023, a security researcher demonstrated that Duolingo's public API could be abused to scrape user profile data at scale. By January 2023, a dataset of 2.6 million user records had been scraped and was being sold; by August 2023 it had been posted for free on a hacking forum, making it widely available.
What Data Was Exposed
The scraped data included usernames, real names (where provided), email addresses, and data related to users' language-learning activity and courses. Passwords were not part of this dataset, as it was obtained via API scraping rather than a direct database breach.
Why This Still Matters
Even breaches from years ago remain a risk today. Stolen data is sold, traded, and reused indefinitely. Credentials from old breaches fuel credential stuffing attacks — automated attempts to reuse your email and password combination on other sites. If you reused a password anywhere, one old breach can compromise several current accounts.
How to Check If You Were Affected
Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.
What to Do If You Were Affected
- Change any reused password immediately, starting with your most sensitive accounts.
- Enable two-factor authentication wherever it's offered.
- Monitor financial accounts closely if payment or banking data was involved.
- Watch for phishing — breach data is often used to craft convincing scam messages.
- Freeze your credit if your SSN or government ID number was exposed.
👉 Check your own exposure in 30 seconds → scan your email free.
Frequently Asked Questions
When did the Duolingo data leak happen?
The underlying API vulnerability was reported in early 2023. A dataset of 2.6 million scraped records was being sold by January 2023 and was posted for free on a hacking forum in August 2023.
Was Duolingo actually hacked?
Not in the traditional sense. Attackers abused a publicly accessible API endpoint to scrape user profile data at scale rather than breaching Duolingo's internal database directly, but the practical result for affected users is the same: their data is exposed.
What data was exposed in the Duolingo leak?
Usernames, real names where provided, email addresses, and language-course activity data were scraped. Passwords were not included in this particular dataset.
How do I check if my Duolingo account was affected?
Use the free checker at Scan My Shadow with your email address. If it appears, be alert for phishing emails that reference your Duolingo account or learning activity.
Did Duolingo fix the vulnerability?
Duolingo stated it addressed the API abuse and implemented additional rate-limiting and monitoring to prevent large-scale scraping going forward.