Skip to main content
Breach Signal

Breach report

Social Media

Twitter (X)

Twitter confirms zero-day used to expose data of 5.4 million accounts

A Twitter API bug introduced in 2021 let attackers link private email addresses and phone numbers to about 5.4 million accounts. The dataset was sold on a hacking forum before Twitter confirmed the flaw.

Reported by BleepingComputer

Records exposed

5.4M

About 5.4 million accounts

Scale vs. largest on file

When
2021–2022
How they got in
API vulnerability abused to match emails and phone numbers to accounts
Sector
Social Media

In July 2022, a seller on the Breached hacking forum offered a database of more than 5.4 million Twitter accounts, asking $30,000. Each record tied a private email address or phone number to a Twitter profile, along with public information such as the display name, location, follower count and profile picture. On August 5, 2022, Twitter confirmed that the data had been compiled by exploiting a vulnerability in its systems.

The flaw stemmed from a code change Twitter made in June 2021. It allowed anyone who submitted an email address or phone number to Twitter's systems to learn whether it was associated with an account and, if so, which one. By running large lists of emails and numbers through the bug, attackers could build a directory linking otherwise hidden contact details to specific profiles, including pseudonymous ones.

Twitter learned of the issue in January 2022 through its bug bounty program on HackerOne, where a researcher reported it, and said it fixed the problem promptly. At the time the company said it had no evidence of exploitation. The appearance of the dataset months later showed otherwise. Twitter said it would notify affected account holders it could identify but acknowledged it could not confirm every impacted user. Reports indicated that multiple buyers acquired the data, and it was later released publicly for free.

The incident carried special risk for people who rely on anonymity, such as activists, dissidents and journalists, since the leak could expose the real-world contact information behind an anonymous handle. Ireland's Data Protection Commission, Twitter's lead European regulator, opened an inquiry in late 2022. The exposure also added to scrutiny from the US Federal Trade Commission, which had already penalized Twitter earlier that year over its misuse of phone numbers and emails collected for security purposes.

The 5.4 million record leak turned out to be only the first visible piece of a much larger scraping operation using the same bug, which later surfaced as a dataset of more than 200 million email addresses. It stands as a textbook example of an enumeration vulnerability: a lookup feature that confirms whether contact details exist can be abused at scale. Platforms that offer contact discovery need strict rate limits and should avoid confirming account existence to unauthenticated requests.

More from the wire

More in Social Media.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.