Data leak

Have I Been Pwned / Twitter privacy blog / CSO Online

πŸ“… 2021-06-01 🏒 Twitter / X
Primary Source β†—

Incident Details

Twitter API change in June 2021 introduced vulnerability allowing anyone to look up Twitter accounts via email/phone. Threat actors scraped at scale before patch in Jan 2022. 200-235M email addresses linked to Twitter profiles posted for sale/free on hacking forums in Jan 2023. Dataset merged email addresses (private) with public profile data (username, bio, followers). Ireland DPC opened GDPR investigation. Twitter/X did not formally notify affected users. No passwords included.

Technical Details

Initial Attack Vector
CWE-284: Improper Access Control (unauthenticated API endpoint allowed email-to-account enumeration)
Vendor / Product
Twitter / X

Timeline

  1. 2021-06-01 Breach occurred
  2. 2023-01-04 Publicly disclosed
  3. unknown Customers notified