Breach report
MessagingSnapchat (Snap Inc.)
4.6 Million Snapchat Usernames And Phone Numbers Captured By API Exploit
On New Year's Eve 2013, hackers published usernames and phone numbers for about 4.6 million Snapchat users, harvested through a Find Friends flaw that researchers had warned the company about days earlier.
Reported by Forbes
Records exposed
4.6M
About 4.6 million accounts
Scale vs. largest on file
- When
- 2013–2014
- How they got in
- API abuse of the "Find Friends" contact-matching feature
- Sector
- Messaging
In the final hours of 2013, a website called SnapchatDB posted a downloadable database containing the usernames and phone numbers of roughly 4.6 million Snapchat users, along with their general geographic region. The operators blurred the last two digits of each phone number, saying they wanted to limit spam and abuse, but warned that an uncensored version could follow. The site was taken offline within hours, though copies had already spread.
The data was collected by abusing Snapchat's Find Friends feature, which let users upload their phone contacts to see which of them were on the service. The underlying API did not adequately limit how many lookups could be made, so attackers could submit enormous batches of phone numbers and receive back the matching usernames. Australian group Gibson Security had published details of the weakness on Christmas Day, after saying it had warned Snapchat months earlier. Snapchat responded publicly that such an attack was theoretically possible and that it had added countermeasures, only for the mass dump to appear days later.
The people behind SnapchatDB said their aim was to pressure the company to take security seriously. The incident was especially sensitive because Snapchat's audience skewed young, meaning many exposed phone numbers belonged to teenagers. Critics also pointed out that linking phone numbers to usernames undermined the pseudonymity many users assumed the app provided.
Snapchat soon released an app update that let users opt out of having their phone number linked to their username in Find Friends and required new users to verify their numbers. It also imposed rate limits on the API. The episode became part of a broader Federal Trade Commission case: in May 2014, Snapchat settled FTC charges that it had misled users about how ephemeral their messages were and about its security practices, with the regulator specifically citing the failure to secure Find Friends that led to the 4.6 million record leak. The settlement imposed 20 years of independent privacy monitoring.
The Snapchat leak is an early example of what would become a recurring problem across social platforms: contact-discovery features that can be turned into bulk enumeration tools. Similar flaws later surfaced at Facebook, Twitter and others, reinforcing that rate limiting and abuse detection are essential security controls, not optional extras.