
It was only a week ago that hackers were able to gather personal information from billions of Facebook and LinkedIn accounts and were put for sale on the internet. It now seems as if Clubhouse had fallen prey to a similar attack. The audio-only chatting platform oversaw more than 1.3 million users having their records stolen and posted online on a popular hacker forum.
This means that consumers had all the data from their Clubhouse profiles leaked which consisted of their:
- Full Names
- User ID and username
- Number of followers and followings
- Other social media account handles
- Account creation dates
- Invites sent and who they were invited by on the app
Is Clubhouse’s API Susceptible to Allowing Mass Scrapes of User Data?
Clubhouse later came forward with a statement regarding the issue, claiming that they did not observe any form of a security breach in their systems. They went ahead and stated that the leaked data was already public information available to anyone and easily accessible through their API(Application Programming Interface).
These comments did little to ease the general public’s concerns and their user base, as this event showcased the position of Clubhouse with regards to their privacy policy. Public information was obtainable for a large number of accounts through Clubhouse’s API, which can have severe ramifications for user privacy.
Mantas Sasnauskas, a senior information security researcher at CyberNews, called this policy into question, stating that the platform allowed anyone with a token or an API to collect the entire library of public profile information from the Clubhouse app without an expiration period in place for said token.
He further added that despite Clubhouse having a privacy policy in place which does not permit unauthorized data mining and data scraping, they should take measures to make it difficult for anyone to scrape user data, rather than just writing a few sentences against it in their policy.
How Can This Impact Users?
The consequence of the public data being leaked online is that cybercriminals can use it to carry out attacks such as phishing and social engineering attacks. On the hacker forum mentioned above, the SQL database posted revealed only public Clubhouse profile information. There were no signs of sensitive data, such as credit card information, present for any user. However, for certain cybercriminals, this basic public information is sufficient and useful in their efforts to commit heinous acts against innocent individuals using these apps.
These individuals are able to compare information found in the leaked SQL database with other data breaches through which they create comprehensive profiles of their targets. This sets a platform for them to conduct identity theft against the people whose information they can find readily available on the hacker forum.
Next Steps
There are a few necessary steps that you must undertake if you are fearful that your Clubhouse profile information has been leaked and published online. This includes:
- Avoid accepting Clubhouse connection requests from dodgy people who you do not know.
- Going forward, create strong passwords and use a password manager tool to help you remember them.
- Begin enabling two-factor authentication for all your accounts.
- Be wary of suspicious emails and messages you receive online, as these can contain links that may lead to your privacy being compromised.