A threat actor has claimed to have breached King of the Curve, an MCAT preparation platform that provides gamified study tools through web and mobile applications. The actor alleges the stolen dataset contains hundreds of thousands of customer profiles alongside more than 26 million application event records. The claims have not been independently verified.
According to the forum post, the alleged breach includes approximately 330,853 unique customer profiles and 26.3 million activity events spanning the platform. The dataset is being offered as a free download on a cybercrime forum.
Educational platform allegedly targeted
King of the Curve provides online preparation tools for the Medical College Admission Test (MCAT), including practice questions, quizzes, games, progress tracking, and personalized study features for aspiring medical students.
The threat actor claims the exposed customer profiles contain email addresses, phone numbers, names, dates of birth, demographic information, educational history, employment status, household income, and institutional details. The post also alleges the data includes MCAT study progress, previous exam scores, target scores, practice performance, study preferences, onboarding information, and subscription status.
In addition to customer profile data, the actor claims the breach includes more than 26 million application event records containing device identifiers, IP addresses, advertising identifiers, session information, and user activity telemetry collected through the platform.
Large behavioral dataset allegedly included
Unlike many breach claims that primarily involve contact information, the alleged King of the Curve dataset appears to center heavily on user behavior within the application. According to the listing, the records include study habits, question performance, subject difficulty ratings, learning preferences, marketing attribution data, and detailed engagement metrics collected over time.
If authentic, the combination of personal information and long-term behavioral data could present elevated privacy risks for affected users, particularly because the platform serves students preparing for professional entrance examinations.
Part of an ongoing series of breach claims
The same threat actor has recently published several alleged datasets involving customer analytics and application telemetry. BreachNews previously reported similar claims involving Mailshake and Ling App, among other organizations, where large exports of user profiles and event data were also offered for download.
While the actor has consistently provided detailed descriptions of the purported datasets, each claim should be evaluated on its own merits until independently verified or confirmed by the affected organization.
Company has not publicly addressed the claim
King of the Curve had not issued any public statement regarding the alleged breach at the time of publication.
If confirmed, the incident could expose sensitive personal, educational, and behavioral information associated with hundreds of thousands of users. BreachNews will update this article if the company responds or additional evidence emerges supporting or refuting the claim.












