Disclosed Aug 5, 20224 years ago6,682,453 accountsConfirmed
API flaw let attacker link emails and phone numbers to Twitter accounts
Twitter confirmed that a bug reported in January 2022 let anyone submitting an email or phone number learn the linked account, and that a bad actor exploited it before the fix and offered the data for sale. The seller claimed profiles of 5.4 million accounts; Twitter did not give a count.
What is known
| People affected | 6,682,453 (accounts in the leaked data, per Have I Been Pwned) |
|---|---|
| Disclosed | Aug 5, 2022 |
| Discovered | Jan 2022 |
| Happened | Jan 1, 2022 |
| Attack | Hacking |
| Data exposed | Emails, Location, Names, Phone numbers |
| Sector | Media · US |
| Status | Confirmed |
| Check your email | Have I Been Pwned |
Sources
| Source | |
|---|---|
| Have I Been Pwned: Twitterhaveibeenpwned.com · Aggregator | Aggregator |
| An incident impacting some accounts and private information on Twitterprivacy.twitter.com · The organization | The organization |
| Twitter confirms zero-day used to expose data of 5.4 million accountsbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Aug 5, 2022 | |
| Have I Been Pwnedaccounts in the data | Aug 13, 2022 | 6,682,453 |
Other breaches at Twitter
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Scraped emails and profiles of over 200 million Twitter users posted onlineJan 5, 20233 years agoScrapingUnverified | Jan 5, 20233 years ago | Scraping | Tech | Unverified | 212Macct |
| Protected tweets bug notified late; Irish DPC fine of EUR 450,000Dec 15, 20205 years agoExposed data | Dec 15, 20205 years ago | Exposed data | Tech | Settled | Unknown |
| Phone spear phishing gives attackers internal tools, 130 accounts targetedJul 15, 20206 years agoPhishing | Jul 15, 20206 years ago | Phishing | Tech | Confirmed | 130 |
| Hackers gained admin control of Twitter twice in 2009; FTC security orderJun 24, 201016 years agoHacking | Jun 24, 201016 years ago | Hacking | Tech | Settled | Unknown |
History of this record
- 2026-09-25 · source_type: aggregator to company · seed source
- 2026-09-25 · source_url: https://haveibeenpwned.com/Breach/Twitter to https://privacy.twitter.com/en/blog/2022/an-issue-affecting-some-anonymous-accounts · seed source
- 2026-09-25 · status: disclosed to confirmed · seed source
- 2026-09-25 · verified_by: empty to research · seed source
- 2026-09-25 · verified: 0 to 1 · seed source
- 2026-09-25 · country: empty to US · seed source
- 2026-09-25 · sector: tech to media · seed source
- 2026-09-25 · attack: unknown to hacking · seed source
- 2026-09-25 · disclosed: 2022-08-13 to 2022-08-05 · seed source
- 2026-09-25 · discovered: empty to 2022-01 · seed source
- 2026-09-25 · summary: In January 2022, a vulnerability in Twitter's platform allowed an attacker to build a database of the email addresses and phone numbers of millions of users of the social platform . In a disclosure notice later shared in August 2022, Twitte to Twitter confirmed that a bug reported in January 2022 let anyone submitting an email or phone number learn the linked account, and that a bad actor exploited it before the fix and offered the data for sale. The seller claimed profiles of 5. · seed source
- 2026-09-25 · title: empty to API flaw let attacker link emails and phone numbers to Twitter accounts · seed source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Have I Been Pwned), confirmed by Research. Record counts are as reported. Not legal advice.