Twitter API data exposure

API vulnerability allowing phone/email-to-account lookup. 200M+ account records scraped and later leaked.

Last modified

Summary

  • Environment: Social media
  • Operational impact: 200M+ account records scraped and later leaked
  • Financial impact: No financial figure is established by the reviewed source evidence
  • Record status: Developing record. Reviewed September 19, 2026; updated as evidence emerges.

What happened

In Jan 2022 (disclosed), X experienced an incident in its social media environment. The retained source describes the attack path as follows: API vulnerability allowing phone/email-to-account lookup. [1]

The documented consequence was: 200M+ account records scraped and later leaked. [1]

Impact

  • Documented impact: 200M+ account records scraped and later leaked. [1]
  • No financial loss, ransom amount, recovery cost, or regulatory penalty is established by the reviewed source evidence.

Threat Group & Attack Vector

The retained source describes the attack path as follows: API vulnerability allowing phone/email-to-account lookup. The canonical record does not add intrusion steps beyond those supported by the source. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

Response

The retained source describes containment action intended to limit further access or disruption. [1]

This account is bounded to Update about an alleged incident regarding user data sold online. Details absent from that evidence are left unresolved rather than inferred. [1]