Ling App Allegedly Breached With Nearly 6 Million User Profiles Claimed Exposed

A threat actor claims to have breached Ling App, alleging the theft of nearly 6 million user profiles containing account, subscription, device, and application data.
Screenshot of a forum post alleging a data breach involving Ling App. The post claims nearly 6 million user profiles were stolen, lists the alleged data categories, and includes a download link that has been redacted by BreachNews.
Forum post alleging a breach of Ling App and claiming the theft of nearly 6 million user profiles containing account information, subscription data, device metadata, and application activity.

A threat actor has claimed to have breached Ling App, a language learning platform with millions of downloads, alleging the theft of nearly 6 million user profiles spanning 2022 through November 2025. The claims have not been independently verified.

According to the forum post, the alleged dataset contains 5,970,006 user profiles, including approximately 2.38 million unique email addresses, more than 3.49 million unique IP addresses, and information relating to 166,446 paying subscribers. The actor is offering the purported data as a free download, although BreachNews has not accessed or verified the files.

Claimed dataset extends beyond contact information

Ling App offers interactive language courses, AI-assisted learning features, and speech recognition across more than 60 languages. The threat actor claims the exported data includes both account information and detailed application telemetry.

According to the post, the alleged dataset contains email addresses, names, IP addresses, city and regional location data, device identifiers, operating system information, authentication methods, advertising identifiers, Firebase authentication IDs, subscription product information, payment status, lifetime revenue, transaction identifiers, purchase and expiration timestamps, application version details, and event metadata.

The actor also claims each profile contains hundreds of application properties related to language learning activity, including target language, languages studied, learning streaks, study time, onboarding information, motivation settings, and other user preferences.

Potential risks if authentic

If authentic, the combination of personal information, subscription details, device metadata, and behavioral analytics could increase the risk of phishing, credential attacks, and targeted social engineering. Paying subscribers could also face more convincing fraud attempts referencing subscription or billing activity.

Although the post references transaction identifiers and payment status, it does not claim that full payment card numbers were included in the alleged dataset.

Latest claim from low-history forum account

The forum account responsible for the post has limited posting history, and the listing was not accompanied by publicly available evidence sufficient to independently verify the alleged breach.

The claim follows two other alleged datasets recently published by the same account involving workforce management platform ZoomShift and mobile pet grooming platform Groomit. At present, there is no evidence linking the alleged incidents beyond their publication by the same account.

No public statement from Ling App

Ling App had not issued any public statement regarding the alleged breach at the time of publication.

As with any newly published breach claim from an unestablished source, the authenticity, scope, and origin of the purported dataset remain unverified. BreachNews will update this article if Ling App confirms an incident or additional evidence emerges.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site