About 6.7 million Twitter emails sat in the 2022 API reverse-lookup file — phones and profile fields on many rows, not passwords. Check whether your address is in that file, then treat a matched number as the first job.
Quick answer — was Twitter breached?
Yes — this page is the January 2022 Twitter API reverse-lookup incident, about 6.7 million unique emails with phones and public profile fields. Passwords were not included. It is not the 200 million-email dump. A match means your address appeared in that smaller file. Check if you were affected.
What happened in the Twitter data breach?
This catalog row is the smaller Twitter / X API reverse-lookup file — about 6.7 million unique email addresses — not the 211-million-email dump and not a password theft. In January 2022 a vulnerability let operators submit an email address or phone number and receive the matching account. Twitter later said the bug had been introduced in June 2021, that it patched the issue, and that it was notifying some people in August 2022. The listed fields include email or phone plus public profile data: username, display name, bio, location, and profile photo. A separate list of about 1.4 million addresses from suspended accounts sat alongside the live-account set.
Passwords were not in the file. The durable harm is a phone number or inbox sitting next to a real handle. A published number is raw material for SMS phishing and for SIM-swap attempts that try to steal text-message login codes. A published inbox is a phishing hook. Bios and locations make the mail sound local. Changing an X password does not unsay the number.
Press first described a sale of about 5.4 million user records, then free posts of that set. This lookup’s unique-email count is 6.7 million across active and suspended accounts. That is a counting difference, not a second company hack. The high-demand “200 million Twitter emails” story is the other slug: [Twitter (200M)](/breaches/twitter200m/). Learn more about what a data breach means for you.
Why was the Twitter breach so dangerous?
Passwords were not in the file. The durable harm is a phone number or inbox sitting next to a real handle. A published number is raw material for SMS phishing and for SIM-swap attempts that try to steal text-message login codes. A published inbox is a phishing hook. Bios and locations make the mail sound local. Changing an X password does not unsay the number.
Yes, for the phone-and-phishing playbook, not the password playbook. Numbers and emails from 2021–2022 are still useful in 2026. A password change alone does not fix this match. Move important accounts off SMS codes, treat unexpected texts as hostile, and assume your number can be looked up next to your handle.check whether your email was exposed in this breach.
What data was stolen in the Twitter breach?
Bios — may be combined with other breach data to build a profile for targeted attacks
Email addresses — used for phishing attacks and credential stuffing against your other accounts
Geographic locations — may be combined with other breach data to build a profile for targeted attacks
Names — used to build profiles and target you with personalised scams
Phone numbers — enables SIM-swapping attacks and targeted SMS phishing
Profile photos — may be combined with other breach data to build a profile for targeted attacks
Usernames — used to build profiles and target you with personalised scams
Timeline of the Twitter breach
June 2021
Twitter later says a bug that lets contact details resolve to accounts is introduced
December 2021–January 2022
Operators abuse the API to build email- and phone-linked profile sets; Twitter patches the flaw in January 2022
August 2022
A set of about 5.4 million Twitter records is offered for sale; Twitter publishes a notice and says it is notifying some people
August 2022
This catalog row is added at about 6.7 million unique emails across active and suspended accounts
November 2022
The 5.4 million-record set is posted freely; contemporaneous reporting lists phones or emails plus public profile fields
January 2023
A separate ~200 million-email scrape is published — listed here as Twitter (200M), not this slug
2022–2026
Copies remain in phishing and SIM-swap kits; published numbers and emails stay useful
Is the Twitter breach still dangerous in 2026?
Yes, for the phone-and-phishing playbook, not the password playbook. Numbers and emails from 2021–2022 are still useful in 2026. A password change alone does not fix this match. Move important accounts off SMS codes, treat unexpected texts as hostile, and assume your number can be looked up next to your handle.
Phone numbers and bios do not expire. An authenticator app or a hardware key ages SMS-based takeover out of your life. Learn how long stolen data stays dangerous.
Is this the 200 million-email Twitter dump?
No. The high-demand story people mean by “the Twitter / X breach” is usually Twitter (200M): a 2021 email-to-profile scrape published in January 2023, about 211.5 million unique inboxes, without phone numbers in that catalog row.
This slug is the earlier, smaller file Twitter discussed in August 2022. Industry-standard breach data sources list it under the plain Twitter name with a January 2022 date. The data types here include phone numbers, bios, locations, and profile photos. Do not invent a 200-million-row hit from this page.
Both files come from API reverse-lookup abuse, not from a stolen password table. The playbook is still de-anonymisation, phishing, and — on this row — phone-number risk.
- This row — January 2022 API file, ~6.7 million emails, phones and richer profile fields.
- Twitter (200M) — January 2023 publication of a 2021 email scrape, ~211.5 million inboxes.
- Neither file contains passwords. Do not merge them into one story.
What does an EmailLeaked Twitter match mean?
If your address is in the 6.7-million-email file, EmailLeaked shows a named Twitter match the same way it shows any other named incident. The row is a lookup against industry-standard breach data sources. We do not claim an exclusive copy of the 5.4-million-record sale, and we do not crawl hidden markets live.
A match is not proof someone is inside your X session this week. It is evidence that the address — and typically a phone number or profile fields from that era — appeared in a file that has been public since 2022. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.
If you want the response order in one place, use what to do after a data breach and the phone playbook there. For a second public index, see free data breach checkers. Closing an account you no longer use is the X delete guide.
What to do if your email was in the Twitter breach
Confirm the match and which Twitter file it is
Run the email check if you need the named incidents in one list. This Twitter row lists phones and profile fields, not passwords. The large dump is Twitter (200M).
Check this email — freeMove important logins off SMS codes
Turn on two-factor authentication with an authenticator app or a hardware key on email, banking, and X. A published number makes a text-message code easier to steal via SIM swap or SMS phishing.
Treat unexpected texts and “X security” mail as hostile
The file gives scammers a handle, a number or inbox, and often a bio or location. Do not tap links in surprise reset messages. Walk the account security checklist.
Open the account checklistFollow the after-breach playbook
Use the first-hour and 24-hour lists, then the phone / email-only playbook. A Twitter match on this page is not the password-leak playbook unless a different incident also listed passwords.
Open the after-breach playbookCompare how public checkers differ
A second lookup does not unsay a published number. It can show you how different public indexes present the same named incident.
Read the checker comparisonClose X if you no longer use it
Deletion does not unsay the published number or handle. It stops a leftover X login from sitting around. Deactivate, wait out the window, then lock the email that still recovers other accounts.
How to delete your X (Twitter) accountFrequently asked about the Twitter breach
Which Twitter / X incident is this page about?
Is this the 200 million-email Twitter leak?
Were passwords exposed in this Twitter file?
Why do articles say 5.4 million and this page says 6.7 million?
How does EmailLeaked show a Twitter match?
Is this Twitter file still dangerous in 2026?
How this breach page is reviewed
Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.
Sources
Last updated: September 2026
Other major breaches
Was your email in this breach?
Check if your email appeared in the Twitter breach and 1033+ other known breaches — free, instant, no signup.
Check my email — freeWas my email hacked?
Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.
Check my email now — it's freeNo signup required · Results in under 5 seconds · Your data is never stored