About 211 million email addresses were published in January 2023 from a 2021 Twitter API scrape — inboxes tied to public profiles, not passwords. Check whether your address is in that file, then treat a matched handle as a phishing target.
Quick answer — was Twitter (200M) breached?
Yes — this page is the 2021 Twitter / X email-to-profile scrape released in January 2023, about 211.5 million unique emails. Passwords were not included. It is not the smaller 2022 Twitter catalog row. A match means your address appeared in that profile file. Check if you were affected.
What happened in the Twitter (200M) data breach?
This catalog row is the large Twitter / X email-to-profile scrape published in early 2023 — not a password-database theft, and not the smaller 2022 API file listed under the plain Twitter slug. Operators abused an API that, given an email address, returned the matching Twitter profile. The collection happened in 2021, before Twitter patched the flaw in January 2022. In January 2023 a cleaned file of more than 200 million rows was posted on a hacking forum. Independent counting of unique inboxes put this lookup at about 211.5 million email addresses plus public profile fields such as names, usernames, and follower counts.
Passwords were not in the file. Changing an X password does not unsay the binding of a real inbox to a handle. That binding is the harm: de-anonymisation for people who used a sensitive address on a pseudonymous account, and a ready list for phishing that names the handle. Contemporaneous reporting said this particular dump did not include phone numbers. Phone risk belongs to the separate, smaller Twitter catalog row.
Press in late 2022 also described a larger ~400 million set offered for sale; reporters treated the January 2023 post as a de-duplicated slice of that market, still containing some repeats. Ireland’s Data Protection Commission was already looking at an earlier, smaller Twitter API leak. That investigation is context. It is not proof that this 211-million-email row and the 6.7-million-email row are the same file. Learn more about what a data breach means for you.
Why was the Twitter (200M) breach so dangerous?
Passwords were not in the file. Changing an X password does not unsay the binding of a real inbox to a handle. That binding is the harm: de-anonymisation for people who used a sensitive address on a pseudonymous account, and a ready list for phishing that names the handle. Contemporaneous reporting said this particular dump did not include phone numbers. Phone risk belongs to the separate, smaller Twitter catalog row.
Yes, for the email-and-identity playbook, not the password playbook. Addresses tied to handles in 2021 are still useful in 2026. A password change alone does not fix this match. Use a dedicated inbox for social accounts if you still need a pseudonym, move important logins off SMS codes, and treat unexpected “X security” mail as hostile.check whether your email was exposed in this breach.
What data was stolen in the Twitter (200M) breach?
Email addresses — used for phishing attacks and credential stuffing against your other accounts
Names — used to build profiles and target you with personalised scams
Social media profiles — may be combined with other breach data to build a profile for targeted attacks
Usernames — used to build profiles and target you with personalised scams
Timeline of the Twitter (200M) breach
June 2021–January 2022
A Twitter API bug lets operators submit an email (or, in related abuse, a phone number) and receive the matching account
2021
This large email-to-profile corpus is compiled; public profile fields are joined to the resolved inboxes
January 2022
Twitter patches the API flaw after a bug-bounty report
Late 2022
Markets advertise a much larger Twitter contact file, sometimes described as about 400 million rows
5 January 2023
A de-duplicated post of more than 200 million Twitter profiles appears on a hacking forum; unique-email counts settle near 211.5 million
2023–2026
Copies remain in phishing and people-search kits; published inbox-to-handle pairs stay useful. The smaller Twitter slug stays a separate row
Is the Twitter (200M) breach still dangerous in 2026?
Yes, for the email-and-identity playbook, not the password playbook. Addresses tied to handles in 2021 are still useful in 2026. A password change alone does not fix this match. Use a dedicated inbox for social accounts if you still need a pseudonym, move important logins off SMS codes, and treat unexpected “X security” mail as hostile.
An email-to-handle binding does not expire. An authenticator app ages SMS-based takeover out of your life. Learn how long stolen data stays dangerous.
Is this the same as the other Twitter / X breach page?
No. EmailLeaked keeps two Twitter catalog rows because the public indexes do. This slug — Twitter (200M) — is the large 2021 email-resolution scrape published in January 2023. The listed types are email addresses, names, usernames, and social-media profiles. There are no passwords and no phone numbers on this row.
The other page, Twitter, is a smaller January 2022 API incident: about 6.7 million unique emails, with phone numbers, bios, locations, and profile photos on many rows. Twitter said that bug was introduced in June 2021 and that it notified some people in August 2022. Same class of failure — reverse-lookup through an API — different file, different date added, different fields.
Neither row is a copy of Twitter’s password vault. Do not treat a match here as proof that an X password leaked. If you want the response order, use what to do after a data breach and the email / phishing playbook there.
- This row — 2021 scrape, published January 2023. ~211.5 million emails + public profile fields. No passwords.
- The other Twitter slug — ~6.7 million emails, phones and richer profile fields, added August 2022.
- A password change is hygiene, not a cure for a published inbox-to-handle pair.
What does an EmailLeaked Twitter (200M) match mean?
If your address is in the 2023 published file, EmailLeaked shows a named Twitter (200M) match the same way it shows any other named incident. The row is a lookup against industry-standard breach data sources. We do not claim an exclusive copy of the forum dump, and we do not crawl hidden markets live.
A match is not proof someone is inside your X session this week. It is evidence that the address — and typically a name and username from that era — appeared in a file that has been public since January 2023. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.
If you want to test a reused password from some other incident without sending the full password, use the password leak checker. For a second public index, see free data breach checkers. Closing an account you no longer use is the X delete guide.
What to do if your email was in the Twitter (200M) breach
Confirm the match and which Twitter file it is
Run the email check if you need the named incidents in one list. This Twitter (200M) row lists emails and public profile fields, not passwords. The smaller Twitter row is a different file.
Check this email — freeTreat unexpected X / Twitter mail as hostile
The file gives scammers a handle next to an inbox. Do not tap reset links in surprise messages. Walk the account security checklist for sessions, recovery contacts, and leftover apps.
Open the account checklistMove important logins off SMS codes
Turn on two-factor authentication with an authenticator app or a hardware key on email and on X. A published inbox makes phishing easier even when this particular file has no phone numbers.
Follow the after-breach playbook
Use the first-hour and 24-hour lists, then the email-only / phishing playbook. A Twitter (200M) match on this page is not the password-leak playbook unless a different incident also listed passwords.
Open the after-breach playbookCompare how public checkers differ
A second lookup does not unsay a published inbox-to-handle pair. It can show you how different public indexes present the same named incident.
Read the checker comparisonClose X if you no longer use it
Deletion does not unsay the published inbox-to-handle pair. It stops a leftover X login from sitting around. Deactivate, wait out the window, then lock the email that still recovers other accounts.
How to delete your X (Twitter) accountFrequently asked about the Twitter (200M) breach
What is the Twitter 200 million-record file?
Were passwords in the Twitter 200M dump?
Is this the same as /breaches/twitter/?
I used a fake name on Twitter — am I exposed anyway?
How does EmailLeaked show a Twitter (200M) match?
Is the Twitter 200M scrape still dangerous in 2026?
How this breach page is reviewed
Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.
Sources
Last updated: September 2026
Other major breaches
Was your email in this breach?
Check if your email appeared in the Twitter (200M) breach and 1033+ other known breaches — free, instant, no signup.
Check my email — freeWas my email hacked?
Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.
Check my email now — it's freeNo signup required · Results in under 5 seconds · Your data is never stored