Over the last weekend, we started to hear reports of a data leak related to the Clubhouse application. A report from CyberNews claimed that important data related to 1.3 million Clubhouse users has been leaked. The data was taken from the SQL database and was posted on a well-known hacker forum for free.
Clubhouse's alleged leaked data includes details like user ID, name, photo URL, username, Instagram/Twitter handle, followers/following count, account creation date, and name of the user who invited them. It does not seem like any sensitive information was leaked and this is something the company has acknowledged as well.
Paul Davison, CEO of Clubhouse, has officially denied all the reports about the data leak. He said that the data posted on the forum include already publically available information. The Verge has quoted him as saying, “No, This is misleading and false, it is a clickbait article, we were not hacked. The data referred to was all public profile information from our app. So the answer to that is a definitive ‘no.’”
The company also tweeted through the official Twitter account to debunk all the claims. It talked similar things about the data being publically available but added that it can be accessed by anyone using the app or its API. This latter part of the statement has raised some eyebrows as many believe that despite being public information, it should not allow anyone to scrap details of so many users so easily.
This is misleading and false. Clubhouse has not been breached or hacked. The data referred to is all public profile information from our app, which anyone can access via the app or our API. https://t.co/I1OfPyc0Bo
— Clubhouse (@joinClubhouse) April 11, 2021
As things stand now, it seems like the leaked data of Clubhouse does not feature any private information. There are questions over the company's handling of the public data but we can expect a fix in the near future. Interestingly, another huge data leak related to a whopping 533 million Facebook users was reported just last week.