1020+ breaches tracked — check free
EmaiLeaked
travel_explore Email checker lock Password checker database Recent breaches menu_book Data breach guide article Blog group About
search Check my email now
Privacy Terms Contact Editorial standards Disclaimer

Twitter (200M)

Medium

In early 2023, a dataset containing approximately 200 million Twitter (now X) email addresses was published freely on a criminal forum after circulating in paid markets for roughly a year. The data had been compiled in 2021 and 2022 by exploiting a vulnerability in Twitter's API that allowed any user to submit an email address and receive the associated Twitter account in return — effectively enabling bulk reverse-lookup of the platform's user base. Twitter patched the vulnerability in January 2022.

211.5M
Records exposed
2021
Year
4
Data types
Free
To check
Check if you were affected — free

Quick answer — was Twitter (200M) breached?

Yes. Twitter (200M) was breached in January 2021, exposing 211,524,284 records including email addresses, names, social media profiles. This breach has been independently verified. If your email was involved, your data may still be at risk today. Check if you were affected.

What happened in the Twitter (200M) data breach?

In early 2023, a dataset containing approximately 200 million Twitter (now X) email addresses was published freely on a criminal forum after circulating in paid markets for roughly a year. The data had been compiled in 2021 and 2022 by exploiting a vulnerability in Twitter's API that allowed any user to submit an email address and receive the associated Twitter account in return — effectively enabling bulk reverse-lookup of the platform's user base. Twitter patched the vulnerability in January 2022.

The breach exposed the link between real-world email addresses and Twitter accounts, enabling de-anonymisation of users who had deliberately maintained pseudonymous identities on the platform. Journalists, activists, whistleblowers, and individuals from countries with restrictive governments were among those most seriously affected. The exposure also enabled targeted phishing campaigns against verified high-value accounts and public figures.

Ireland's Data Protection Commission — the lead EU data protection regulator for Twitter — opened a formal investigation into the handling of the breach. The API vulnerability had been reported to Twitter through its bug bounty programme in January 2022 but was not publicly disclosed until the data surfaced in circulation later that year. Learn more about what a data breach means for you.

Why was the Twitter (200M) breach so dangerous?

The breach exposed the link between real-world email addresses and Twitter accounts, enabling de-anonymisation of users who had deliberately maintained pseudonymous identities on the platform. Journalists, activists, whistleblowers, and individuals from countries with restrictive governments were among those most seriously affected. The exposure also enabled targeted phishing campaigns against verified high-value accounts and public figures.

Don't wait to find out — check if your email was exposed in this breach.

What data was stolen in the Twitter (200M) breach?

Email addresses Names Social media profiles Usernames

Email addresses — used for phishing attacks and credential stuffing against your other accounts

Names — used to build profiles and target you with personalised scams

Social media profiles — may be combined with other breach data to build a profile for targeted attacks

Usernames — used to build profiles and target you with personalised scams

Timeline of the Twitter (200M) breach

January 2022

Security researcher reports API vulnerability to Twitter through bug bounty; Twitter patches the flaw

2022

Data compiled using the vulnerability before the patch begins circulating in paid criminal markets

December 2022

Multiple security researchers confirm 400 million records available for sale on criminal forums

January 2023

Approximately 200 million email–account pairs published freely; widely downloaded

2023

Ireland's DPC opens formal investigation; affected users notified

Is the Twitter (200M) breach still dangerous in 2026?

Yes. Stolen data from the Twitter (200M) breach remains dangerous years after the incident. Attackers routinely compile data from multiple breaches to build complete profiles, and credentials from 2021 are still actively used in automated attacks today.

Personal information like email addresses, phone numbers, and dates of birth does not expire. Even if you changed your Twitter (200M) password, the other exposed data can be combined with information from other breaches to target you. Learn how long stolen data stays dangerous.

What to do if your email was in the Twitter (200M) breach

1

Change your Twitter (200M) password immediately

Log into Twitter (200M) and change your password to something strong and unique — one you have never used anywhere else.

2

Change any account sharing that password

If you reused this password elsewhere, change it on every affected account. Attackers test stolen credentials against hundreds of popular sites within hours.

3

Enable two-factor authentication

Turn on 2FA on Twitter (200M) and every important account. Even if your password is known, attackers cannot access the account without the second factor.

4

Check your other accounts for this breach

Run a full email scan to see every breach your address appears in — not just this one.

Check all my breaches — free

Frequently asked about the Twitter (200M) breach

How was the Twitter 200 million record dataset compiled?
Attackers exploited a vulnerability in Twitter's API that, when given an email address or phone number, returned the associated Twitter account. By submitting millions of email addresses, they built a reverse-lookup database linking real-world identities to Twitter handles. The vulnerability was patched in January 2022 but not before the bulk of the data had been collected.
Were passwords included in the Twitter 200M breach?
No. This dataset contained only email addresses linked to Twitter account data (usernames, follower counts, verification status). No passwords were exposed. The primary risk is de-anonymisation and targeted phishing rather than direct account takeover.
I use a pseudonymous Twitter account — am I affected?
If you registered your Twitter account with your real email address, the breach links your email to your pseudonymous handle. Anyone with access to the dataset can now connect your real identity to your public Twitter presence. This is particularly concerning for individuals who used Twitter anonymously for safety reasons.
What can I do if my email appeared in the Twitter 200M breach?
You cannot undo the de-anonymisation. Going forward: use a dedicated email address for social media accounts to limit cross-platform linkage. Enable two-factor authentication on your Twitter/X account. Be alert for phishing emails targeting your Twitter identity — especially if your account has a large following.

How this breach page is reviewed

Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.

Was your email in this breach?

Check if your email appeared in the Twitter (200M) breach and 1018+ other known breaches — free, instant, no signup.

Check my email — free

No signup · Under 2 seconds · Never stored

Was my email hacked?

Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1019+ known breaches.

Check my email now — it's free

No signup required · Results in under 5 seconds · Your data is never stored