To delete your X (Twitter) account after a breach, sign in on x.com, download your archive, go to Settings → Your account → Deactivate your account, then stay signed out through the waiting period. Last updated: August 2026.
X still holds old Twitter usernames, DMs, and the same email you used in 2016. If that email was in a leak, you lost the login, or you want the handle gone, deactivation is post-breach hygiene. Attackers love leftover social passwords because people reuse them on email.
The high-demand Twitter 200 million email dump is a 2021–2023 profile scrape, not a password-database theft. A smaller 2022 API file is a separate catalog row. As of 2026, more than 12 billion stolen credentials remain in known datasets. Verizon’s 2024 Data Breach Investigations Report again put stolen credentials at the centre of many web-application breaches.
Why would you delete an X account after a data breach?
- The email on the account showed up in a breach check
- You were locked out after a SIM swap or a reused password
- A joke or brand account still uses your personal Gmail
- You already moved to a new handle and this one is idle
If you still use X for news or work, lock it: unique password, 2FA, app passwords reviewed. Deletion is for the account you will not miss.
Should you deactivate X or only change the password?
X’s consumer flow is deactivate, then wait. That is their delete. Changing the password is the keep path.
Paid X subscriptions should be cancelled in settings first so billing does not continue in a confusing way.
If you typed the password into a fake “unusual login” page, check the password and use the leaked-password checklist.
How do you delete your X account step by step?
1. Open x.com yourself. Do not use a link from an email that says your account will be terminated. Check the URL if you are unsure.
2. Download your archive. Settings → Your account → Download an archive of your data. It can take hours.
3. Unlink apps. Settings → Security and account access → Apps and sessions. Revoke anything you do not recognise.
4. Settings → Your account → Deactivate your account. Read whether connected ads or professional tools are included.
5. Confirm with your password.
6. Stay signed out for the full waiting period. The mobile app will try to pull you back in. That is how people reactivate by accident.
7. Change the email’s password if it was shared. Prefer Gmail 2FA if that is the inbox.
Check if your email was exposed → free checker
What should you do before you deactivate X?
- Save media you might need; the archive is the official copy
- Remove the phone number if it is also your bank 2FA
- Change “Log in with Twitter” on leftover apps — those buttons still exist on old sites
- Tell co-admins of a shared brand account
- Check the email
What happens to your data after you delete X?
After the window, the profile should stop serving. Google results lag. Third-party mirrors of old tweets can remain. X may retain some logs for legal reasons.
Breach files already copied emails and passwords. Deactivation does not un-copy them. People-search pages are broker opt-out work.
What if you cannot sign in to delete X?
Use official password reset to the recovery email or phone. Recover Gmail only after other sites can live without that inbox.
Without access you cannot deactivate. Starve the email of remaining resets and treat the handle as burned.
Direct messages are where people send one-time codes and photos they should not. Download the archive if those threads matter for a dispute. After deactivation, you will not have a friendly “export again” button. Screenshots in your camera roll are not a substitute for the official archive if you need timestamps.
If your handle was impersonated, report the fake from a signed-in session before you deactivate, using X’s in-product reporting. Closing your real account does not automatically take down a copycat. Bookmark x.com yourself so a search ad cannot send you to a lookalike.
How do you protect other accounts after X is gone?
Email first. Then any site that still offered Twitter OAuth. Use the account security checklist. For the broader cleanup order, use what to do after a data breach and the password reuse change checklist.
Expect “reactivate to save your handle” phishing. Paste links into website-check.
Frequently asked questions
Is deactivating X the same as deleting it?
X uses deactivation as the close-account step. After you deactivate, a waiting period applies. Signing in during that window typically reactivates the account. There is not a separate “instant wipe” button for most people.
How long does X wait before the account is gone?
The product has used a 30-day window for a long time, but you should read the current confirmation screen. Do not tweet from the account if you want the timer to finish.
Can I delete X if I cannot log in after a breach?
Use X’s official password reset on x.com. If the recovery email is also burned, recover email first. You cannot finish deactivation without access. Ignore “Twitter recovery” DMs.
Will deleting X remove old tweets from Google?
X should stop showing the profile after the window. Search engines and archives can lag or keep copies. Download an archive first if the posts matter.
Should I delete X or just change the password?
Keep it if you still use it: unique password and two-factor authentication. Delete leftover brand or joke accounts still tied to a leaked email. Those are extra doors.
Did an old Twitter breach include my email?
Email and password pairs from Twitter-era incidents still circulate. Check your address with a free breach check and see our Twitter breach explainer for what those dumps contained.