In the last few months, Clubhouse has taken the internet by storm with its unique features, even as experts remained unsure about how safe the platform was, as shown in this article by India Today. Unfortunately for the users, the feats have come true, and the platform has allegedly suffered a database breach. To make matters worse, even if you don’t have an account on Clubhouse, chances are there that your phone number is compromised.
Clubhouse, which is a live audio-only social media app, allegedly suffered a database breach with around 3.8 billion phone numbers of the user and their phonebook are up for sale on Darknet.
“A database of 3.8 billion phone numbers of #Clubhouse users is up for sale on the #Darknet. It also contains numbers of people in the user’s phonebooks that were synced. So chances are high that you are listed even if you haven’t had a Clubhouse login,” cybersecurity expert Jiten Jain wrote on Twitter.
Another cybersecurity expert Marc Ruef wrote, “These are not just members but also people in contact lists that were synced. Chances are high that you are listed even if you haven’t had a Clubhouse login.”
The app was launched in March 2020 as an invite-only app and was made available only on iOS. But with its growing popularity, especially in India, the company opened the doors for Android users recently. This month, they launched their beta version and removed the “invite-only” option, making the app available for all users.
Clubhouse refuted data leak claims in response to an e-mail sent by EastMojo. “There has been no breach of Clubhouse. There are a series of bots generating billions of random phone numbers.”
“In the event that one of these random numbers happens to exist on our platform due to mathematical coincidence, Clubhouse’s API returns no user identifiable information,” the statement added.
The company added that they respect user’s privacy and said, “Privacy and security are of the utmost importance to Clubhouse and we continue to invest in industry-leading security practices.”
“The alleged news of contact leaks on Darknet is touted to be incorrect by the experts on Twitter as well,” the company said.
Rajshekhar Rajaharia, Internet Security Researcher wrote, “Seems completely fake. There are only mobile numbers without the name, photos. This list of phone numbers can be generated very easily.”
Another Twitter user, who claims to be a cyber expert wrote, “That threat actor is simply scamming users on that forum. His sample is just random Japanese phone numbers with no other personal info. Anyone can post a random list of numbers like that, in fact, uses some no. generating the script.”
In April this year, it was alleged that the personal data of 1.3 million Clubhouse users was leaked. However, Clubhouse CEO Paul Davison had denied such news.
In early 2021, cybersecurity researchers at Stanford University’s Stanford Internet Observatory (SIO) said that the app is allegedly leaking audio data to the Chinese government.
