Data breach
X (Twitter)
- Records
- 2,873,876,432
- Breach date
- 2 April 2025Estimated
- Added
- 2 April 2025
What was exposed
2 types of data
- Usernames2,873,876,432
- Email addresses201,686,654
About this breach
A massive dataset tied to X (formerly Twitter) has surfaced online, and our investigation team estimates it contains roughly 2.87 billion rows, including screen names for that many accounts and email addresses linked to about 201.7 million of them. Reporting from UNILAD and Fox News describes a 34 GB CSV file with more than 201 million user records, posted in early April 2025 by a forum user known as "ThinkingOne" on BreachForums. The file was free to download for anyone with a forum account.
The data does not appear to come from a single fresh hack of X's systems. According to GRC Report, ThinkingOne said the 2.8 billion record dataset covers essentially every X screen name as of mid-November 2022 and was leaked in January 2025. He merged it with an older dataset, collected in 2021 and leaked in January 2023, that included email addresses, then published the combined records. He also claimed X never responded to his attempts to report the leak. Researchers at SafetyDetectives reviewed a sample and found the profile details matched live X accounts, though they could not confirm every email belonged to the listed account. Our investigation team estimates the breach date as April 2, 2025, and no actor has claimed responsibility.
Breach Timeline
January 2023: A dataset of roughly 200 million X user records, collected in 2021, leaked online and included email addresses.
January 23, 2025: A separate dataset of about 2.8 billion X user IDs and screen names, reportedly collected in November 2022, leaked online, per ThinkingOne's account to GRC Report.
Late March 2025: ThinkingOne posted the merged 34 GB file containing 201,186,753 records on BreachForums, where researchers at SafetyDetectives found it.
What Information Was Compromised?
Our analysis found the following data types in this breach: screen names (user handles), numerical X user IDs, and email addresses. External reporting on the merged file also points to full names, self-disclosed locations, account creation dates, follower counts, time zones, current and former display names, and profile image references.
No passwords, direct messages, or financial data appeared in the published file, according to the researchers who examined it.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main risk is phishing. An email address tied to a real name, location, and account history gives scammers material for convincing messages that impersonate X, banks, or delivery services. Attackers can also use the emails for credential stuffing, testing password combinations stolen from other sites against X logins. Because X said it found no evidence of a new intrusion and the leak itself contained no passwords, direct account takeover is not guaranteed, but reused passwords make it possible. Publicly tying an email address to a person's profile also raises the risk of doxxing and targeted harassment.
What Should You Do If You Were Affected?
Change your X password and make it unique. Do not reuse a password from another site.
Turn on two-factor authentication for X and your email account.
Check other accounts that use the same email and password combination and update those passwords, starting with your primary email.
Be skeptical of unexpected emails or direct messages referencing your X account, even ones that look official. Do not click links or enter credentials from links in messages.
Watch for unexplained password reset emails or login alerts on any account.
Review your X privacy settings and limit personal details, such as your location, on your public profile.
