5.4M user records published (API vulnerability)
Data compromised
Email addresses, Phone numbers
Technical writeup
Hacker published email/phone for 5.4M users; had exploited API bug in late 2021, tried to sell for $30k in July. Part of larger 200M+ scrape.
Root cause
API vulnerability (submit email/phone, get account).