惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
有赞技术团队
有赞技术团队
宝玉的分享
宝玉的分享
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog
V
V2EX
大猫的无限游戏
大猫的无限游戏
博客园 - 司徒正美
D
Docker
T
The Blog of Author Tim Ferriss
罗磊的独立博客
博客园 - 叶小钗
酷 壳 – CoolShell
酷 壳 – CoolShell
Blog — PlanetScale
Blog — PlanetScale
月光博客
月光博客
J
Java Code Geeks
Jina AI
Jina AI
博客园 - 【当耐特】
C
Check Point Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
腾讯CDC
Last Week in AI
Last Week in AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
Visual Studio Blog

Consumer Insights

Weverse data breach affects 422,584 user accounts Manchester Airports Group cyberattack exposes data of 8.7 million customers Sakura Internet hack may affect 1.36 million accounts French tax authority breach exposes data of 678,000 people and businesses Phone number leaked in the Bloctel breach? Here’s what to do. SplitVPN breach reveals 58 million hidden connection logs South Korea diplomatic academy hack exposes diplomat data Credential stuffing attack at Chick-fil-A comes with data breach notice for customers Coca-Cola halts Fairlife production across US after ransomware attack Qantas data breach started with a fake IT support call Lidl warns customers after data breach How to find out if your identity has been exposed by infostealers Texas breach exposes PII of 3 million hunting and fishing license customers Maine forced to take down data breach portal after fake notices filed with authorities Carnival breach exposes data of nearly 6 million people 7-Eleven data breach exposes data of 185,000 people UK Water Supplier Fined Nearly £1 Million After Hackers Roamed Networks for Almost 2 Years DAEMON Tools Lite breach prompts urgent update after malware-laced installer Instructure confirms breach; millions of Canvas users potentially impacted Stalkerware data leak exposes private screenshots linked to celebrities and influencers Rituals data breach exposes customer details Booking.com says breach exposed travelers’ data Basic-Fit data breach exposes member information across Europe Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data Lapsus$ claims AstraZeneca breach exposes code and credentials Aura data breach exposes 900,000 records after phishing attack Telus Digital data breach confirmed after ShinyHunters claims 1PB theft Was Your Data Exposed in the Latest Under Armour Breach? Here’s What You Should Do Breach at Tinder, Hinge and OkCupid exposes user data Europe Fines Big Tech €1.2 Billion under GDPR in 2025
Hackers claim to have breached Udemy, stealing 1.4 millio...
Alina BÎZGĂ · 2026-04-27 · via Consumer Insights

Notorious hacking group ShinyHunters recently announced they had breached Udemy’s systems and exfiltrated a large dataset of user information.

Key takeaways:

  • Hackers claim to have stolen 1.4 million Udemy user records
  • The company has not confirmed the breach
  • Stolen information may include personal and internal data
  • Attackers are using a “pay or leak” extortion tactic
  • Users should update passwords, enable 2FA, and watch out for scams

What happened?

On April 24, 2026, the cybercriminal group ShinyHunters issued a “pay or leak” ultimatum, warning Udemy that they had breached their systems and that over 1.4 million records, including internal corporate data, would be made public if their demands were not met.

“Over 1.4M records containing PII and other internal corporate data have been compromised. Pay or Leak,” ShinyHunters said on their leak site. “This is a final warning to reach out by 27 Apr 2026 before we leak, along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline.”

What data was allegedly exposed?

According to Haveibeenpwned, the breach includes an extensive dataset. The reportedly compromised data may include:

  • Email addresses
  • Full names
  • Phone numbers
  • Physical addresses
  • Employers
  • Job titles
  • Payment method information

At the time of writing, the breach remains unconfirmed by Udemy.

If the data is legitimate, exposed information could be used in targeted phishing campaigns, credential stuffing attacks on other platforms, and account takeover attempts.

What should Udemy users do?

Even though the breach is still unconfirmed, it’s a good time to double-check your security.

Start with the basics and update your passwords. If you’ve used your Udemy password elsewhere, change it and don’t forget to enable 2FA, which adds an extra barrier that can stop many automated attacks.

Be cautious with incoming messages. Expect phishing attempts that reference courses, certificates, or account issues. Use free scam detection tools like Scamio and Link Checker to verify suspicious links before interacting.

And finally, keep an eye out for potentially exposed data. Services like Bitdefender Digital Identity Protection are designed for exactly this kind of situation.

Even if this breach claims turns out to be false, the service continuously monitor for your personal data across known leaks. If your information does surface in a confirmed breach, you’ll get real-time alerts and clear steps to secure your identity.