Skip to main content
Breach Signal

Breach report

Messaging

Snapchat (Snap Inc.)

4.6 Million Snapchat Usernames And Phone Numbers Captured By API Exploit

On New Year's Eve 2013, hackers published usernames and phone numbers for about 4.6 million Snapchat users, harvested through a Find Friends flaw that researchers had warned the company about days earlier.

Reported by Forbes

Records exposed

4.6M

About 4.6 million accounts

Scale vs. largest on file

When
2013–2014
How they got in
API abuse of the "Find Friends" contact-matching feature
Sector
Messaging

In the final hours of 2013, a website called SnapchatDB posted a downloadable database containing the usernames and phone numbers of roughly 4.6 million Snapchat users, along with their general geographic region. The operators blurred the last two digits of each phone number, saying they wanted to limit spam and abuse, but warned that an uncensored version could follow. The site was taken offline within hours, though copies had already spread.

The data was collected by abusing Snapchat's Find Friends feature, which let users upload their phone contacts to see which of them were on the service. The underlying API did not adequately limit how many lookups could be made, so attackers could submit enormous batches of phone numbers and receive back the matching usernames. Australian group Gibson Security had published details of the weakness on Christmas Day, after saying it had warned Snapchat months earlier. Snapchat responded publicly that such an attack was theoretically possible and that it had added countermeasures, only for the mass dump to appear days later.

The people behind SnapchatDB said their aim was to pressure the company to take security seriously. The incident was especially sensitive because Snapchat's audience skewed young, meaning many exposed phone numbers belonged to teenagers. Critics also pointed out that linking phone numbers to usernames undermined the pseudonymity many users assumed the app provided.

Snapchat soon released an app update that let users opt out of having their phone number linked to their username in Find Friends and required new users to verify their numbers. It also imposed rate limits on the API. The episode became part of a broader Federal Trade Commission case: in May 2014, Snapchat settled FTC charges that it had misled users about how ephemeral their messages were and about its security practices, with the regulator specifically citing the failure to secure Find Friends that led to the 4.6 million record leak. The settlement imposed 20 years of independent privacy monitoring.

The Snapchat leak is an early example of what would become a recurring problem across social platforms: contact-discovery features that can be turned into bulk enumeration tools. Similar flaws later surfaced at Facebook, Twitter and others, reinforcing that rate limiting and abuse detection are essential security controls, not optional extras.

More from the wire

More in Messaging.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.