Breach report
Social MediaTwitter (X)
200 million Twitter users' email addresses allegedly leaked online
A dataset tying more than 200 million email addresses to Twitter accounts was released on a hacking forum in January 2023, scraped years earlier through an API flaw that Twitter had patched in 2022.
Reported by BleepingComputer
Records exposed
212M
More than 200 million accounts (about 211.5 million unique email addresses)
Scale vs. largest on file
- When
- 2021 (leaked 2023)
- How they got in
- API vulnerability abused to match email addresses to accounts
- Sector
- Social Media
On January 4, 2023, a threat actor released a collection of roughly 200 million Twitter user records on the Breached hacking forum for almost nothing. Each entry linked an email address to a Twitter account, along with the user's name, handle, follower count and account creation date. Breach-notification service Have I Been Pwned analyzed the files and counted about 211.5 million unique email addresses.
The data traced back to the same API weakness behind the earlier 5.4 million account leak. Introduced in 2021, the flaw allowed anyone to submit an email address or phone number and learn which Twitter account it belonged to. Scrapers used it to process enormous lists of addresses before Twitter fixed the bug in January 2022. In late 2022 a larger, messier version of the dataset, advertised as containing some 400 million records, circulated among criminals; the January release was a cleaned-up, de-duplicated version.
Twitter was in turmoil at the time. Elon Musk had acquired the company in October 2022, and several senior privacy and security staff had resigned in November. In a statement on January 11, 2023, Twitter said its investigation found no evidence that the recently circulated datasets were obtained by exploiting a vulnerability in its systems and suggested the data was likely a compilation of already public information. Security researchers disputed that framing, noting that the link between private email addresses and accounts was not public.
The leak widened Twitter's regulatory exposure. Ireland's Data Protection Commission was already investigating the related 2022 incident under GDPR, and the US Federal Trade Commission was monitoring the company's compliance with an existing consent order on data protection. Researchers warned that the dataset could be used to unmask anonymous accounts, craft convincing phishing emails that referenced a victim's real handle, and target high-profile users for account takeover.
The breach illustrated how a single enumeration bug can generate harm long after it is patched, as data scraped before the fix continues to be traded and repackaged. For users, the practical guidance was to watch for Twitter-themed phishing, enable app-based two-factor authentication, and consider using a separate email address for accounts meant to be pseudonymous.