Clubhouse denied the claims of a data breach that began circulating online last week. The clarification came when a cybersecurity expert claimed that a database of 3.8 billion phone numbers allegedly belonging to Clubhouse users is up for sale on the Dark Web. In a tweet, specialist Jiten Jain attached a screenshot from the hacker who claims the database includes users' mobile phones, landlines, private and business phones. The screenshot further notes that “Clubhouse connects in real time to the phone directories of all its users, meaning every time you add a new phone number to your phone directory, the number is automatically added to Clubhouse's secret database.” The hacker claimed the data is valued at $3 billion, which also includes the numbers of “celebrity” people.
See also: Saudi Aramco: Hackers stole 1 TB of data and are selling it on the dark web

See also: Greek man accused by the US of selling data on the dark web
In a statement to news agency IANS, Clubhouse denied these claims and said: “There is a series of bots that generate billions of random phone numbers.” Speaking about Clubhouse’s alleged “secret database,” the company clarified by saying, “if one of these random numbers happens to exist on our platform due to mathematical coincidence, the Clubhouse API does not return any identifying information from the user.”
Several experts have examined the issue, refuting the hacker's claims. Security researcher Rajshekhar Rajaharia told the news agency that this list of phone numbers can be generated very easily and the alleged data leak claim appears to be false. Another researcher, Sunny Nehra, noted that the hacker is relatively new to this forum and does not usually make such claims. Earlier in April, Clubhouse denied another breach claim after a report claimed that a database containing 1.3 million user files of the platform was posted on a popular hacking forum.
See also: ZeroFox: Acquires dark web threat firm Vigilante
Overall, Clubhouse users do not need to worry about their data at this time. However, it is imperative that everyone follows the recommended cybersecurity best practices. Users should also continue updating their passwords and adding two-factor authentication wherever possible.
Information source: news18.com
