Udemy suffered a data breach affecting 1.4 million accounts, with customer and instructor information including email addresses, names, addresses, phone numbers, and payment methods exposed.
What happened
According to HIBP, online training company Udemy was targeted by the ShinyHunters group in April 2026 in a "pay or leak" extortion attempt. The attackers subsequently released the stolen data publicly.
What was exposed
The breach exposed data for 1.4 million unique email addresses belonging to Udemy customers and instructors. Exposed information included names, physical addresses, phone numbers, employer information, and instructor payout methods such as PayPal, cheque, and bank transfer details.
Who is affected
Approximately 1.4 million Udemy customers and instructors were affected by the breach.
What to do now
If you have a Udemy account, monitor your email and financial accounts for suspicious activity. Consider changing your Udemy password and reviewing any linked payment methods for unauthorized transactions. Be cautious of phishing attempts targeting affected users.