Data breach
- Records
- 16,082,464
- Breach date
- 1 January 2016Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses16,082,464
- Passwords16,080,142
About this breach
Millions of Twitter credentials tied to a 2016 incident have surfaced in the index, and our investigation team estimates the dataset contains 16,082,464 records, including roughly 16,080,142 passwords and 16,082,464 email addresses. The incident traces back to mid-2016, when a large cache of Twitter login details was offered for sale on the dark web. Twitter itself said at the time that its systems had not been breached, and independent analysis suggested the credentials were harvested from users' own infected computers rather than stolen from the company. For that reason, this listing is best understood as a credential collection affecting Twitter account holders, not a confirmed intrusion into Twitter's servers.
Breach Timeline
June 8, 2016: LeakedSource, a site that indexes leaked login data, reported receiving more than 32.8 million Twitter records, including email addresses, usernames, and plaintext passwords, from a seller using the alias "Tessa88," who was asking about 10 bitcoins for the data, according to TechCrunch and The Week.
June 2016: Twitter denied that its systems had been breached. "We are confident that these usernames and credentials were not obtained by a Twitter data breach," a spokesperson told TechCrunch.
Mid-September 2016: Twitter banned LeakedSource's account on the platform after the service indexed the Twitter records, which were most likely obtained through malware that logged users' credentials, according to BleepingComputer.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords. News reporting from June 2016 described the wider cache, which LeakedSource put at 32,888,300 records, as containing usernames, email addresses, sometimes a second email address, and plaintext passwords, meaning passwords were not encrypted.
Not every individual is affected by every type of data listed here.
LeakedSource said it verified the data by asking 15 users whether the passwords listed for their accounts were correct, and all 15 confirmed they were. The analysis also found many weak passwords in the set, including common choices such as "123456" and "password," and noted that many of the affected accounts appeared to belong to users in Russia, based on the email domains in the data.
What Are the Potential Risks for Affected Individuals?
Because passwords were stored in plaintext, anyone who obtains this dataset can try to log into the corresponding accounts directly. If you reused the same password on other sites, and many people do, those accounts are at risk through credential stuffing, where attackers replay stolen email and password pairs across other services. Stolen credentials can also support phishing, since a real email address and a working password make a fraudulent message far more convincing. An attacker who reaches an email account can often reset passwords for many other services tied to that address.
What Is Twitter Doing in Response?
Twitter's position, stated in June 2016 and reported by TechCrunch, was that its systems were not breached and that the credentials likely came from malware on users' devices that captured passwords saved in browsers such as Chrome and Firefox. The company said it was checking its data against other recent password leaks to help protect accounts. Its trust and information security officer at the time, Michael Coates, also publicly stated that Twitter's systems had not been compromised. No further company response tied specifically to this indexed dataset was confirmed as of September 25, 2026.
What Should You Do If You Were Affected?
Change your Twitter password, and change it anywhere else you reused it.
Turn on two-factor authentication for your Twitter account and your primary email account.
Be cautious with emails or messages asking you to log in, especially ones citing a security problem.
If you saved passwords in your browser, consider moving them to a password manager and reviewing saved entries for anything outdated.
