Twitter (200M)

Medium

About 211 million email addresses were published in January 2023 from a 2021 Twitter API scrape — inboxes tied to public profiles, not passwords. Check whether your address is in that file, then treat a matched handle as a phishing target.

211.5M
Records exposed
2021
Year
4
Data types
Free
To check
Check if you were affected — free

Quick answer — was Twitter (200M) breached?

Yes — this page is the 2021 Twitter / X email-to-profile scrape released in January 2023, about 211.5 million unique emails. Passwords were not included. It is not the smaller 2022 Twitter catalog row. A match means your address appeared in that profile file. Check if you were affected.

What happened in the Twitter (200M) data breach?

This catalog row is the large Twitter / X email-to-profile scrape published in early 2023 — not a password-database theft, and not the smaller 2022 API file listed under the plain Twitter slug. Operators abused an API that, given an email address, returned the matching Twitter profile. The collection happened in 2021, before Twitter patched the flaw in January 2022. In January 2023 a cleaned file of more than 200 million rows was posted on a hacking forum. Independent counting of unique inboxes put this lookup at about 211.5 million email addresses plus public profile fields such as names, usernames, and follower counts.

Passwords were not in the file. Changing an X password does not unsay the binding of a real inbox to a handle. That binding is the harm: de-anonymisation for people who used a sensitive address on a pseudonymous account, and a ready list for phishing that names the handle. Contemporaneous reporting said this particular dump did not include phone numbers. Phone risk belongs to the separate, smaller Twitter catalog row.

Press in late 2022 also described a larger ~400 million set offered for sale; reporters treated the January 2023 post as a de-duplicated slice of that market, still containing some repeats. Ireland’s Data Protection Commission was already looking at an earlier, smaller Twitter API leak. That investigation is context. It is not proof that this 211-million-email row and the 6.7-million-email row are the same file. Learn more about what a data breach means for you.

Why was the Twitter (200M) breach so dangerous?

Passwords were not in the file. Changing an X password does not unsay the binding of a real inbox to a handle. That binding is the harm: de-anonymisation for people who used a sensitive address on a pseudonymous account, and a ready list for phishing that names the handle. Contemporaneous reporting said this particular dump did not include phone numbers. Phone risk belongs to the separate, smaller Twitter catalog row.

Yes, for the email-and-identity playbook, not the password playbook. Addresses tied to handles in 2021 are still useful in 2026. A password change alone does not fix this match. Use a dedicated inbox for social accounts if you still need a pseudonym, move important logins off SMS codes, and treat unexpected “X security” mail as hostile.check whether your email was exposed in this breach.

What data was stolen in the Twitter (200M) breach?

Email addresses Names Social media profiles Usernames

Email addresses — used for phishing attacks and credential stuffing against your other accounts

Names — used to build profiles and target you with personalised scams

Social media profiles — may be combined with other breach data to build a profile for targeted attacks

Usernames — used to build profiles and target you with personalised scams

Timeline of the Twitter (200M) breach

June 2021–January 2022

A Twitter API bug lets operators submit an email (or, in related abuse, a phone number) and receive the matching account

2021

This large email-to-profile corpus is compiled; public profile fields are joined to the resolved inboxes

January 2022

Twitter patches the API flaw after a bug-bounty report

Late 2022

Markets advertise a much larger Twitter contact file, sometimes described as about 400 million rows

5 January 2023

A de-duplicated post of more than 200 million Twitter profiles appears on a hacking forum; unique-email counts settle near 211.5 million

2023–2026

Copies remain in phishing and people-search kits; published inbox-to-handle pairs stay useful. The smaller Twitter slug stays a separate row

Is the Twitter (200M) breach still dangerous in 2026?

Yes, for the email-and-identity playbook, not the password playbook. Addresses tied to handles in 2021 are still useful in 2026. A password change alone does not fix this match. Use a dedicated inbox for social accounts if you still need a pseudonym, move important logins off SMS codes, and treat unexpected “X security” mail as hostile.

An email-to-handle binding does not expire. An authenticator app ages SMS-based takeover out of your life. Learn how long stolen data stays dangerous.

Is this the same as the other Twitter / X breach page?

No. EmailLeaked keeps two Twitter catalog rows because the public indexes do. This slug — Twitter (200M) — is the large 2021 email-resolution scrape published in January 2023. The listed types are email addresses, names, usernames, and social-media profiles. There are no passwords and no phone numbers on this row.

The other page, Twitter, is a smaller January 2022 API incident: about 6.7 million unique emails, with phone numbers, bios, locations, and profile photos on many rows. Twitter said that bug was introduced in June 2021 and that it notified some people in August 2022. Same class of failure — reverse-lookup through an API — different file, different date added, different fields.

Neither row is a copy of Twitter’s password vault. Do not treat a match here as proof that an X password leaked. If you want the response order, use what to do after a data breach and the email / phishing playbook there.

  • This row — 2021 scrape, published January 2023. ~211.5 million emails + public profile fields. No passwords.
  • The other Twitter slug — ~6.7 million emails, phones and richer profile fields, added August 2022.
  • A password change is hygiene, not a cure for a published inbox-to-handle pair.

What does an EmailLeaked Twitter (200M) match mean?

If your address is in the 2023 published file, EmailLeaked shows a named Twitter (200M) match the same way it shows any other named incident. The row is a lookup against industry-standard breach data sources. We do not claim an exclusive copy of the forum dump, and we do not crawl hidden markets live.

A match is not proof someone is inside your X session this week. It is evidence that the address — and typically a name and username from that era — appeared in a file that has been public since January 2023. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.

If you want to test a reused password from some other incident without sending the full password, use the password leak checker. For a second public index, see free data breach checkers. Closing an account you no longer use is the X delete guide.

What to do if your email was in the Twitter (200M) breach

1

Confirm the match and which Twitter file it is

Run the email check if you need the named incidents in one list. This Twitter (200M) row lists emails and public profile fields, not passwords. The smaller Twitter row is a different file.

Check this email — free
2

Treat unexpected X / Twitter mail as hostile

The file gives scammers a handle next to an inbox. Do not tap reset links in surprise messages. Walk the account security checklist for sessions, recovery contacts, and leftover apps.

Open the account checklist
3

Move important logins off SMS codes

Turn on two-factor authentication with an authenticator app or a hardware key on email and on X. A published inbox makes phishing easier even when this particular file has no phone numbers.

4

Follow the after-breach playbook

Use the first-hour and 24-hour lists, then the email-only / phishing playbook. A Twitter (200M) match on this page is not the password-leak playbook unless a different incident also listed passwords.

Open the after-breach playbook
5

Compare how public checkers differ

A second lookup does not unsay a published inbox-to-handle pair. It can show you how different public indexes present the same named incident.

Read the checker comparison
6

Close X if you no longer use it

Deletion does not unsay the published inbox-to-handle pair. It stops a leftover X login from sitting around. Deactivate, wait out the window, then lock the email that still recovers other accounts.

How to delete your X (Twitter) account

Frequently asked about the Twitter (200M) breach

What is the Twitter 200 million-record file?
A 2021 scrape that used a Twitter API to resolve email addresses to profiles, then published in January 2023. This catalog row is about 211.5 million unique emails with names, usernames, and other public profile fields. Passwords were not included.
Were passwords in the Twitter 200M dump?
No. This was a reverse-lookup scrape, not a password-database theft. Changing your X password is still wise hygiene. It does not unsay the email-to-handle pair.
Is this the same as /breaches/twitter/?
No. That slug is a smaller January 2022 API file — about 6.7 million unique emails — that also lists phone numbers, bios, locations, and profile photos. Same class of bug, different file.
I used a fake name on Twitter — am I exposed anyway?
If the inbox you registered with is a real address you use elsewhere, this file can still tie that inbox to the handle. The display name being a nickname does not hide the email.
How does EmailLeaked show a Twitter (200M) match?
As a named row in the email checker, using industry-standard breach data sources. This explainer is the plain-English layer: 2021 scrape, published 2023, emails and public profiles, not passwords. We do not claim exclusive ownership of the dump.
Is the Twitter 200M scrape still dangerous in 2026?
Yes, for phishing and de-anonymisation. The bindings of inbox and handle do not expire. Authenticator-app two-factor authentication and skepticism toward unexpected X mail are what age this file out of your life.

How this breach page is reviewed

Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.

Was your email in this breach?

Check if your email appeared in the Twitter (200M) breach and 1033+ other known breaches — free, instant, no signup.

Check my email — free

No signup · Under 2 seconds · Never stored

Was my email hacked?

Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.

Check my email now — it's free

No signup required · Results in under 5 seconds · Your data is never stored