Database containing 1.3M Clubhouse profiles was posted to a hacker forum; Clubhouse says it hasn't been breached, and the data is public info from its app
CyberNews
Context & Ripple Effects
The profile database posting lands after Clubhouse said it had added safeguards when audio and metadata appeared on a third-party website. It also follows reporting that identified limits on deleting user accounts or personal data, making the company’s distinction between a breach and public-profile collection especially consequential.
Clubhouse’s response frames the incident as redistribution of information available through its app rather than unauthorized access. That narrows the immediate technical claim, but keeps attention on how readily app-visible identity data can be compiled and republished.
First-order effects
- Clubhouse must defend its claim that the 1.3M-profile database is public app information, rather than evidence of a breach.
- The hacker-forum post turns individually accessible profile information into a consolidated dataset for forum users.
Second-order effects
- Clubhouse’s earlier security safeguards will face renewed scrutiny because the company had already addressed third-party exposure of audio and metadata.
- The incident sharpens the practical difference between information being public in an app and users consenting to its bulk collection and redistribution.
Third-order effects
- If similar incidents are routinely treated as public-data collection rather than breaches, platform privacy debates will increasingly center on access design and bulk extraction rather than intrusion alone.
- Social platforms that expose profile data may face pressure to define clearer boundaries between ordinary visibility and dataset-scale reuse.
The trend: The story is part of a broader shift in which platform privacy risk is being defined by the public-data permission boundary, not only by whether attackers penetrated a system.
Related: Public-data permission boundary · Clubhouse · Clubhouse adds safeguards after third-party exposure · Clubhouse privacy flaws
Related Coverage
- Clubhouse CEO says user data was not leaked, contrary to reports The Verge
- View article HotHardware.com News
- View article Silicon Republic
- View article International Business Times
- View article Input
- View article KnowTechie
- Clubhouse denies app was hacked as scraped data of 1.3m accounts appears online Memeburn
- View article BGR
- Personal data of 1.3 million Clubhouse users leaked online: Report BGR India
- View article Security Affairs
- Exposed Clubhouse user data raises privacy questions SlashGear
- After Facebook & LinkedIn, now data from Clubhouse leaked - It's of 1.3 million users TechRadar
- LinkedIn denies 500 million user data breach The Record
- Clubhouse CEO Denies Report Of Data Leak For 1.3 Million Users PYMNTS.com
- Scraped data of 1.3 million Clubhouse users published online HackRead
- Over 1.3M Clubhouse user accounts posted to hacker forum AppleInsider
- Personal info for 1.3 million Clubhouse users reportedly leaked online The Verge
- Scraped personal data of 1.3 million Clubhouse users has reportedly leaked online Insider
- LinkedIn confirmed that it was not a victim of a data breach Security Affairs
- Clubhouse CEO contradicts hack reports, says user data was not leaked BGR
- Clubhouse CEO denies that user data has been leaked Gizchina
- More than a million Clubhouse users had their account info leaked online Mashable
- Clubhouse calls report on data breach ‘misleading and false’ The Economic Times
- Clubhouse Says 1.3 Million User Records Shared on Hacker Forum is Public Info iPhone in Canada Blog
- Report: Data of 1.3 Million Clubhouse Users Leaked Online MUO
- Clubhouse data leak: 1.3 million scraped user records leaked online for free DataBreaches.net
Discussion
-
@joinclubhouse
Clubhouse
on x
This is misleading and false. Clubhouse has not been breached or hacked. The data referred to is all public profile information from our app, which anyone can access via the app or our API. https://twitter.com/...
-
@lukerobertmason
Luke Robert Mason
on x
This is WORSE! Clubhouse's API allows anyone access to your personal data. https://twitter.com/...
-
@kimzetter
Kim Zetter
on x
This isn't a hack, and it's inevitable someone would do this. Someone scraped data of 1.3 million Clubhouse users - names, social media profile names, and other dets. Clubhouse says it's all “public profile information from our app, which anyone can access via the app or our API”…
-
@tarah
@tarah
on x
This is not a leak. Clubhouse itself says here “the data referred to is all public...which anyone can access”. This is the way the app was designed to work. https://www.businessinsider.com.au/ ...
-
@parker_gibbons
Parker Gibbons
on x
something hilarious about CH accused of a breach after 1.3mil accounts alongside aggregated personal info leaks and they shoot back with “no, no, no, our API is *supposed* to allow that to happen” https://twitter.com/...
-
@ashindestad
Rabid Wolverine
on x
I thought CH was private and invite-only? How is this information publicly available through your API? That demonstrates very poor security design imo. https://twitter.com/...
-
@tomfgoodwin
Tom Goodwin
on x
Amazed it has to his many users to be honest . Well, downloads may be a more appropriate term https://twitter.com/...
-
@hypervisible
Quantified
on x
Clubhouse says it's not a breach or hack because that data is free and available to anyone. Notice the lack of the sarcasm tag here. https://www.businessinsider.com/ ...
-
@troyhunt
Troy Hunt
on x
I agree with @joinClubhouse. Guidance such as this in the piece is extremely misleading: “If you suspect that your Clubhouse profile data might have been leaked by threat actors [...] Consider using a password manager to create strong passwords and store them securely.” https://t…
-
@pt
Parker
on x
One of these days people are going to stop being surprised that public data is public. But not apparently today. ¯\_(ツ)_/¯ https://twitter.com/...
-
@martinsfp
Martin Sfp Bryant
on x
Clubhouse is keen to point out they've not been hacked. But like the LinkedIn data dump the other day, mountains of scraped public user data is not a good look, even if there's not a lot they can do about it. https://twitter.com/...
-
@dazzagreenwood
@dazzagreenwood
on x
I think there is more to this story. For a start, what is the reasonable expectation of privacy to profile info and what controls should users have over that data? https://twitter.com/...
-
@asaadhannaa
Asaad Hanna
on x
Here we go: #Clubhouse data leak: 1.3 million scraped user records leaked online for free https://cybernews.com/... via @CyberNews
-
@corny_stripes
@corny_stripes
on x
@joinClubhouse Note that doesn't free you from your responsibility to prevent large-scale data collection. Other companies are also held accountable for scrapped data or API abuse (see Facebook).
-
@benmaynard
Benjamin Maynard
on x
@joinClubhouse I fail to see what is false in this headline? Information was extracted on 1.3m users and it was posted online? The fact you make this available via an API using incremental integers for user ID's and implement zero rate limiting kind of makes it worse?!
-
@_danielsinclair
Daniel Sinclair
on x
We should acknowledge that scraping is creepy and unsustainable. We need to work harder to prevent API abuse, and that goes for every product, large or small. https://twitter.com/...
-
@laurahuu
Laura Halminen
on x
So Clubhouse got scraped. Surprised? Not a soul. https://cybernews.com/...
-
@lawyershubkenya
Lawyers Hub Kenya
on x
Clubhouse Data Leak. 1.3 million scrapped user records leaked online for free. What are the impacts of this data breach on Clubhouse users? 🔗https://cybernews.com/ ... #LegalTech #LawTech #Privacy #TechRegulation #LawyersHub
-
@wongmjane
Jane Manchun Wong
on x
The news report mentioned “messages” and “passwords” on Clubhouse, which is inaccurate because CH doesn't have messaging, users don't login using passwords Coincidentally, the near-identical paragraph appears in the LinkedIn data breach report five days ago. This is a copy-paste …
-
@wongmjane
Jane Manchun Wong
on x
The news report mentioned “messages” and “passwords” on Clubhouse, which is inaccurate because CH doesn't have messaging, users don't login using passwords Coincidentally, the near-identical paragraph appears in the LinkedIn data breach report five days ago. This is a copy-paste …
-
@kerempekedis
Kerem
on x
1.3 Milyon Cluphouse kullanıcının bilgileri veri tabanına giren bilgisayar korsanları tarafından ele geçirildi https://www.techmeme.com/...
-
@vmanancourt
Vincent Manancourt
on x
After Facebook and LinkedIn, it seems new kid on the block Clubhouse wants to prove to the big boys that it can leak customer data like the best of them: https://cybernews.com/...
-
@chrismessina
@chrismessina
on x
Scrapers != hackers Google == also a scraper Why do people keep getting this confused? https://twitter.com/...
-
@wongmjane
Jane Manchun Wong
on x
Data of 1 Clubhouse profile, including name, social media handles, profile picture, followers/following count, and more, apparently posted on Twitter The source of this leak told me this is done by opening Clubhouse app, viewing the profile of the victim, and taking a screenshot …
-
@gaberivera
Gabe Rivera
on x
@joinClubhouse Thanks. I can see how the “change the password” stuff is misleading, though the current Techmeme headline reflects what you said here, which addresses that issue. Which part is “false”?
-
@thebookisclosed
Albacore
on x
Can we not use incrementing numbers for user IDs in the year 2021? https://twitter.com/...
-
@rakeshlobster
Rakesh Agrawal
on x
Well that didn't take long. Another reason I'm hyper vigilant about not uploading my entire address books to sites. https://cybernews.com/...
-
@wongmjane
Jane Manchun Wong
on x
Honestly this “hack” is not very impressive at all. Like wow, you looped the API from 1 to 2 to 3 for the otherwise publicly available data. Wow, very technically challenging 👏
-
@wongmjane
Jane Manchun Wong
on x
Not seeing any private info in this “leaked data” of Clubhouse The user IDs are numerical. So it just seems like someone scraped the data by hitting Clubhouse's private API, iterating from user ID 1 to beyond https://twitter.com/...
-
@morqon
Morgan Evetts
on x
Looks like this is scraped, rather than a hack or leak. It's effectively public data available to third parties like @direconcom and https://clubhub.site/ The “Change the password of your Clubhouse account” recommendation is odd, Clubhouse doesn't use passwords to authenticate ht…
-
@itsjeffhiggins
Jeff Higgins
on x
All this seems to be pretty front facing info from a profile page? Is it being aggregated to import elsewhere the issue? https://twitter.com/... https://twitter.com/...
-
@bonnienorman
Bonnie ‘Fully Vaccinated’ Norman
on x
Clubhouse already irritated me with letting me know how many of my friends had joined, even though I have not joined (or given them my email). Clubhouse had my email by accessing the contact list of my friends who have joined. Now this. https://twitter.com/...
-
@martinsfp
Martin Sfp Bryant
on x
Clubhouse continues to face all the challenges larger social apps suffered over years in the space of a few months. A warning to future hit social apps and their investors. https://twitter.com/...
-
@cybernews
@cybernews
on x
So far, it seems like it's been the worst week of the year for social media platforms in terms of data leaks, with #Clubhouse seemingly joining the fray. https://cybernews.com/...
-
@netalexx
@netalexx
on x
It's boring only 1.3 million user records leaked the ‘new normal’ is at least 500 million. 😁 Clubhouse data leak: 1.3 million user records leaked online for free https://cybernews.com/...