← Blog

Twitter Data Breaches: Full Timeline Through 2026

Share on X

People search Twitter data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 14 Twitter-linked incidents, with headline counts up to 330M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why Twitter breach history matters

Twitter operates in Social Media (United States). Across indexed rows, recurring themes include credential theft and social engineering, cloud and database misconfiguration, zero-day exploitation and malware, unverified actor or scraping claims. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2023 — Database of 200M+ users published on BreachForums

Cataloged incident. Data on 200M+ users (emails, names, usernames) published. Scraped via API vulnerability (Jun 2021–Jan 2022). Multiple ransom attempts; Ryushi asked $200k. High-profile accounts included. Exposed categories include Email addresses, Usernames, Names. BreachHistory cites approximately 210M+ affected records in this row. See the ttw2301 and canonical BreachHistory entry.

2022 — 5.4M user records published (API vulnerability)

Cataloged incident. Hacker published email/phone for 5.4M users; had exploited API bug in late 2021, tried to sell for $30k in July. Part of larger 200M+ scrape. Exposed categories include Email addresses, Phone numbers. BreachHistory cites approximately 5.4M+ affected records in this row. See the ttw2211 and canonical BreachHistory entry.

2022 — Zatko whistleblower — security deficiencies

Unverified claim — treat actor counts cautiously. Former head of security Peiter Zatko alleged egregious security deficiencies, misleading regulators, vulnerability to foreign hacking, ~1 serious breach/week. Twitter disputed. Exposed categories include Details not publicly disclosed. No attested victim count is published for this row yet. See the ttw2208 and canonical BreachHistory entry.

2021 — — Twitter: Hacking, 5,400,000 records

Cataloged incident. Zero day vulnerability allowed a threat actor to create profiles of 5.4 million Twitter users inc. a verified phone number or email address. Exposed categories include Personal and demographic data. BreachHistory cites approximately 5.4M+ affected records in this row. See the twitter2021-iib and canonical BreachHistory entry.

2020 — Bitcoin scam — 130 high-profile accounts hijacked

Cataloged incident. Hacker used Twitter internal tools to take over ~130 accounts (Musk, Gates, Obama, etc.) and post Bitcoin scam; over $100k in transfers. Social engineering and employee credentials. Exposed categories include Credentials, Employee data, Internal documents. BreachHistory cites approximately 130 affected records in this row. See the ttw2007 and canonical BreachHistory entry.

2018 — Passwords exposed in internal log — all users advised to change

Cataloged incident. Bug left passwords in internal log unencrypted. No evidence of breach or misuse; Twitter advised all users to change passwords. Exposed categories include Passwords, Internal documents. No attested victim count is published for this row yet. See the ttw1805 and canonical BreachHistory entry.

2018 — — Twitter (X): A glitch caused some passwords to be stored in…

Cataloged incident. May 2018. A glitch caused some passwords to be stored in readable text, visible on the internal computer system. BreachHistory cites approximately 330M+ affected records in this row. See the twitter2018 and canonical BreachHistory entry.

2018 — — Twitter: Poor security / misconfiguration, 33,000,000 records

Cataloged incident. A glitch caused some passwords to be stored in readable text that was visible on Twitter's internal computer system. Exposed categories include Personal and demographic data. BreachHistory cites approximately 33M+ affected records in this row. See the twitter2018-iib and canonical BreachHistory entry.

2017 — — Twitter (X): Thousands of high-profile Twitter accounts have…

Cataloged incident. Thousands of high-profile Twitter accounts have been spewing swastikas and spam following the hack of a popular third-party Twitter service.Sites tied to Amnesty International, BBC's North American service, Forbes magazine, the European Parliament and even tennis star Boris Becker were affected.The hacking traces to third-party analytics service Counter, which bills itself as the #1 stat site powered by Twitter.We're aware that our service was hacked and have started an investigation into the ma Exposed categories include Personal information. No attested victim count is published for this row yet. See the twitter2017 and canonical BreachHistory entry.

2016 — — Twitter (X): Late last week, a password leak hit Twitter, and…

Cataloged incident. Late last week, a password leak hit Twitter, and the company locked millions of user accounts as a result. It was reported that the login credentials of more than 32 million Twitter users were compromised. According to LeakedSource, which indexes hacked credentials from data breaches, the credentials are being traded on the Dark Web for about 10 bitcoin a pop or a little under $6,000. LeakedSource goes on to note that passwords are stored as plain text files, and many seem to be attached to Exposed categories include Personal information. BreachHistory cites approximately 32M+ affected records in this row. See the twitter2016 and canonical BreachHistory entry.

2013 — — Twitter (X): Online attackers were able to access the usernames,…

Cataloged incident. Online attackers were able to access the usernames, email addresses, session tokens, and encrypted passwords of 250,000 users.  Twitter notified affected users and told them to create a new password.  Anyone who used the same password and username or email combination for other sites is encouraged to change the password on other sites as well.UPDATE (03/11/2013): Facebook, Microsoft, and Apple were all affected by a similar breach around the same time. Exposed categories include Personal information. BreachHistory cites approximately 250K+ affected records in this row. See the twitter2013 and canonical BreachHistory entry.

2013 — 250k accounts compromised (Java vulnerability)

Cataloged incident. Attackers gained access to usernames and email addresses. Twitter revoked session tokens and forced password resets. Exposed categories include Email addresses, Passwords, Usernames, Names, Addresses, Session tokens. BreachHistory cites approximately 250K+ affected records in this row. See the ttw1302 and canonical BreachHistory entry.

2011 — — Twitter (X): A 17-year old hacker was charged with various…

Cataloged incident. A 17-year old hacker was charged with various computer crimes.  He somehow managed to access the Twitter, Facebook, PayPal and email accounts of multiple celebrities and other people.  The teen was charged with cyberstalking, computer fraud, computer tampering and extortion. Exposed categories include Personal information. No attested victim count is published for this row yet. See the twitter2011 and canonical BreachHistory entry.

2010 — — Twitter (X): May, 330.0M records

Cataloged incident. May. A glitch caused some passwords to be stored in readable text, visible on the internal computer system. BreachHistory cites approximately 330M+ affected records in this row. See the twitteru1 and canonical BreachHistory entry.

Patterns and analysis

  • Credential theft and social engineering — appears across multiple Twitter catalog entries; prioritize controls that address this class of failure.
  • Cloud and database misconfiguration — appears across multiple Twitter catalog entries; prioritize controls that address this class of failure.
  • Zero-day exploitation and malware — appears across multiple Twitter catalog entries; prioritize controls that address this class of failure.
  • Unverified actor or scraping claims — appears across multiple Twitter catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Bookmark the Twitter company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/twitter · Latest: ttw2301.

Sources: BreachHistory catalog (14 rows for Twitter), company and regulator disclosures cited in individual breach records.