Popular language learning app Duolingo saw a bug exploited that resulted in a compilation of account information from over 2.6 million users. According to VX-Underground, the largest collection of malware source code, samples, and papers on the internet, “sending a valid email to the API returns generic account information on the user (name, email, languages studied).” The data collected will be used for Doxxing.