Data leak
Have I Been Pwned / Twitter privacy blog / CSO Online
Primary Source βIncident Details
Twitter API change in June 2021 introduced vulnerability allowing anyone to look up Twitter accounts via email/phone. Threat actors scraped at scale before patch in Jan 2022. 200-235M email addresses linked to Twitter profiles posted for sale/free on hacking forums in Jan 2023. Dataset merged email addresses (private) with public profile data (username, bio, followers). Ireland DPC opened GDPR investigation. Twitter/X did not formally notify affected users. No passwords included.
Technical Details
- Initial Attack Vector
- CWE-284: Improper Access Control (unauthenticated API endpoint allowed email-to-account enumeration)
- Vendor / Product
- Twitter / X
Timeline
- 2021-06-01 Breach occurred
- 2023-01-04 Publicly disclosed
- unknown Customers notified