A threat actor is claiming to have leaked a database allegedly stolen from AllRightPro, an online English language learning platform, exposing what the actor says are approximately 29,000 user records. The claim surfaced on June 26, 2026 and remains unverified at the time of publication.
AllRightPro provides online English language instruction for children and adults through personalized virtual lessons, interactive learning tools, and digital course materials based on Cambridge educational content. The platform serves students across multiple countries and also manages teacher and business accounts.
Alleged leak includes student, teacher, and company records
According to the forum post, the alleged dataset contains multiple categories of information relating to the platform’s users, educators, and business customers.
The threat actor claims the leaked data includes user roles, usernames, email addresses, names, phone numbers, countries, cities, account creation dates, teacher profiles, and company account information. Sample records shown in the post also reference employee accounts linked to business customers using the platform.
Several of the sample records displayed by the threat actor contain timestamps from 2025 and 2026, which may indicate relatively recent data. However, those timestamps alone do not verify when or how the information was allegedly obtained.
Educational platforms remain attractive targets
Education technology platforms often store a combination of student, teacher, and organizational data in centralized systems. Even where financial information is absent, exposed account data can facilitate phishing campaigns, credential stuffing attacks, account takeover attempts, and social engineering targeting both learners and educators.
If authentic, the alleged dataset could expose relationships between students, instructors, and corporate training customers, providing attackers with information useful for highly targeted phishing campaigns.
Limited evidence accompanies the claim
The listing includes sample records that appear consistent with user account exports, but the threat actor did not provide technical details explaining how the alleged compromise occurred. No evidence has been presented that independently verifies the authenticity, completeness, or freshness of the purported dataset.
The forum account behind the post also has a limited posting history, making it difficult to assess the credibility of the claims based solely on past activity.
No public statement from AllRightPro
AllRightPro had not issued any public statement at time of publication regarding the alleged breach or the authenticity of the leaked data.
As with similar breach listings, the claims should be treated as unverified unless the organization confirms an incident or additional evidence emerges supporting the authenticity of the alleged dataset.












