Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

Twitter Data of 235 Million Accounts Leaked

Twitter Data of 235 Million Accounts Leaked

Randy Hall By Randy Hall Updated Jul 2024 2 min read Share

A dataset purportedly comprising the email addresses and phone numbers of over 400 million Twitter users just a few weeks ago was listed for sale on the hacker forum Breached Forums. The information was initially released on December 23, 2022, by a hacker going by the handle "Ryushi." The attacker demanded $200,000 for an "exclusive" sale of the information. The attacker also warned that the social media platform might face a hefty GDPR charge for failing to secure user data since a fine would be imposed.

Now, the information for 235 million Twitter accounts, including the email addresses used to sign up for them, has been released on an online hacker forum, opening the door for linking anonymous handles to real-world identities.

Security experts warned that individuals who use the social network platform to criticize governments or influential people may be in danger of violence, exposure, arrest, and possibly extortion.

Furthermore, hackers can utilize email addresses to access accounts and reset passwords, particularly those that do not employ two-factor authentication. In addition, hackers can use email addresses to target individuals in phishing attacks.

Alon Gal, co-founder of the security firm Hudson Rock, saw the advertisement on a popular underground marketplace. Gal immediately commented, stating that hackers, political activists, and governments can use the database to undermine privacy.

The data was most likely compiled sometime in the latter half of 2021 by taking advantage of a weakness in Twitter's system. The vulnerability the attackers exploited made it possible for third parties to find Twitter account information with a phone number or email address.

Twitter stated in August that the flaw was unintentionally introduced during a software upgrade seven months earlier and was discovered in January 2022 through Twitter's incentive program for reporting bugs.

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime