A threat actor has claimed to have breached Ling App, a language learning platform with millions of downloads, alleging the theft of nearly 6 million user profiles spanning 2022 through November 2025. The claims have not been independently verified.
According to the forum post, the alleged dataset contains 5,970,006 user profiles, including approximately 2.38 million unique email addresses, more than 3.49 million unique IP addresses, and information relating to 166,446 paying subscribers. The actor is offering the purported data as a free download, although BreachNews has not accessed or verified the files.
Claimed dataset extends beyond contact information
Ling App offers interactive language courses, AI-assisted learning features, and speech recognition across more than 60 languages. The threat actor claims the exported data includes both account information and detailed application telemetry.
According to the post, the alleged dataset contains email addresses, names, IP addresses, city and regional location data, device identifiers, operating system information, authentication methods, advertising identifiers, Firebase authentication IDs, subscription product information, payment status, lifetime revenue, transaction identifiers, purchase and expiration timestamps, application version details, and event metadata.
The actor also claims each profile contains hundreds of application properties related to language learning activity, including target language, languages studied, learning streaks, study time, onboarding information, motivation settings, and other user preferences.
Potential risks if authentic
If authentic, the combination of personal information, subscription details, device metadata, and behavioral analytics could increase the risk of phishing, credential attacks, and targeted social engineering. Paying subscribers could also face more convincing fraud attempts referencing subscription or billing activity.
Although the post references transaction identifiers and payment status, it does not claim that full payment card numbers were included in the alleged dataset.
Latest claim from low-history forum account
The forum account responsible for the post has limited posting history, and the listing was not accompanied by publicly available evidence sufficient to independently verify the alleged breach.
The claim follows two other alleged datasets recently published by the same account involving workforce management platform ZoomShift and mobile pet grooming platform Groomit. At present, there is no evidence linking the alleged incidents beyond their publication by the same account.
No public statement from Ling App
Ling App had not issued any public statement regarding the alleged breach at the time of publication.
As with any newly published breach claim from an unestablished source, the authenticity, scope, and origin of the purported dataset remain unverified. BreachNews will update this article if Ling App confirms an incident or additional evidence emerges.












