Exploiting a previously patched January 2022 API vulnerability, malicious actors scraped public and private profile pairings. The leaked dataset linked public user profiles directly to private email addresses and telephone numbers, which was subsequently shared for free on hacker forums.