DuoLingo "scrape" of 2.6 Million users (email addresses, languages, usernames) sold in forums for $1,500 and advertised as a "breach" and "leak" by media outlets.
For people in the OSINT community, this was already known by inputting an email address and getting back some info from the API. Someone just automated and brute-forced it!
DuoLingo did not take that aspect of privacy into account. Maybe rate limiting the API or authentication could have prevented it?
Maybe a "FREE" 🆓 course from APISec University @apisecu may gave benefited them? (no affiliation to them, I just think it's a great free course, an emerging GAP in #cybersecyrity and here you have a "potential" use case)