In early 2023, a dataset containing approximately 200 million Twitter (now X) email addresses was published freely on a criminal forum after circulating in paid markets for roughly a year. The data had been compiled in 2021 and 2022 by exploiting a vulnerability in Twitter's API that allowed any user to submit an email address and receive the associated Twitter account in return — effectively enabling bulk reverse-lookup of the platform's user base. Twitter patched the vulnerability in January 2022.
Quick answer — was Twitter (200M) breached?
Yes. Twitter (200M) was breached in January 2021, exposing 211,524,284 records including email addresses, names, social media profiles. This breach has been independently verified. If your email was involved, your data may still be at risk today. Check if you were affected.
What happened in the Twitter (200M) data breach?
In early 2023, a dataset containing approximately 200 million Twitter (now X) email addresses was published freely on a criminal forum after circulating in paid markets for roughly a year. The data had been compiled in 2021 and 2022 by exploiting a vulnerability in Twitter's API that allowed any user to submit an email address and receive the associated Twitter account in return — effectively enabling bulk reverse-lookup of the platform's user base. Twitter patched the vulnerability in January 2022.
The breach exposed the link between real-world email addresses and Twitter accounts, enabling de-anonymisation of users who had deliberately maintained pseudonymous identities on the platform. Journalists, activists, whistleblowers, and individuals from countries with restrictive governments were among those most seriously affected. The exposure also enabled targeted phishing campaigns against verified high-value accounts and public figures.
Ireland's Data Protection Commission — the lead EU data protection regulator for Twitter — opened a formal investigation into the handling of the breach. The API vulnerability had been reported to Twitter through its bug bounty programme in January 2022 but was not publicly disclosed until the data surfaced in circulation later that year. Learn more about what a data breach means for you.
Why was the Twitter (200M) breach so dangerous?
The breach exposed the link between real-world email addresses and Twitter accounts, enabling de-anonymisation of users who had deliberately maintained pseudonymous identities on the platform. Journalists, activists, whistleblowers, and individuals from countries with restrictive governments were among those most seriously affected. The exposure also enabled targeted phishing campaigns against verified high-value accounts and public figures.
Don't wait to find out — check if your email was exposed in this breach.
What data was stolen in the Twitter (200M) breach?
Email addresses — used for phishing attacks and credential stuffing against your other accounts
Names — used to build profiles and target you with personalised scams
Social media profiles — may be combined with other breach data to build a profile for targeted attacks
Usernames — used to build profiles and target you with personalised scams
Timeline of the Twitter (200M) breach
January 2022
Security researcher reports API vulnerability to Twitter through bug bounty; Twitter patches the flaw
2022
Data compiled using the vulnerability before the patch begins circulating in paid criminal markets
December 2022
Multiple security researchers confirm 400 million records available for sale on criminal forums
January 2023
Approximately 200 million email–account pairs published freely; widely downloaded
2023
Ireland's DPC opens formal investigation; affected users notified
Is the Twitter (200M) breach still dangerous in 2026?
Yes. Stolen data from the Twitter (200M) breach remains dangerous years after the incident. Attackers routinely compile data from multiple breaches to build complete profiles, and credentials from 2021 are still actively used in automated attacks today.
Personal information like email addresses, phone numbers, and dates of birth does not expire. Even if you changed your Twitter (200M) password, the other exposed data can be combined with information from other breaches to target you. Learn how long stolen data stays dangerous.
What to do if your email was in the Twitter (200M) breach
Change your Twitter (200M) password immediately
Log into Twitter (200M) and change your password to something strong and unique — one you have never used anywhere else.
Change any account sharing that password
If you reused this password elsewhere, change it on every affected account. Attackers test stolen credentials against hundreds of popular sites within hours.
Enable two-factor authentication
Turn on 2FA on Twitter (200M) and every important account. Even if your password is known, attackers cannot access the account without the second factor.
Check your other accounts for this breach
Run a full email scan to see every breach your address appears in — not just this one.
Check all my breaches — freeFrequently asked about the Twitter (200M) breach
How was the Twitter 200 million record dataset compiled?
Were passwords included in the Twitter 200M breach?
I use a pseudonymous Twitter account — am I affected?
What can I do if my email appeared in the Twitter 200M breach?
How this breach page is reviewed
Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.
Other major breaches
Was your email in this breach?
Check if your email appeared in the Twitter (200M) breach and 1018+ other known breaches — free, instant, no signup.
Check my email — freeWas my email hacked?
Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1019+ known breaches.
Check my email now — it's freeNo signup required · Results in under 5 seconds · Your data is never stored