A colossal data exposure—potentially the most extensive social media breach in history—has reportedly revealed 400GB of information from nearly 2.87 billion user profiles on Twitter (now rebranded as X).
Incident Overview and Alleged Origins
On March 28, 2025, an individual using the alias “ThinkingOne” posted on a well-known breach forum, claiming that a disgruntled employee exploited mass layoffs to steal the data. This disclosure marked the first public mention of the leak.
Data Aggregation and File Details
According to ThinkingOne, the newly leaked data was combined with information from an earlier breach in January 2023, which had affected about 209 million users. The merger resulted in a consolidated CSV file—a 34GB dataset that shrinks to 9GB when compressed—containing 201,186,753 entries of users present in both incidents.
ThinkingOne stated, “I tried contacting X via several methods with no response,” which they say forced their hand in making the data public after receiving no feedback from the company. While their investigation suggests the data is genuine, they could not verify that every email address matches the corresponding account.
In-Depth Look at the Exposed Data
Reports from Cyber Press indicate that the leak includes detailed profile metadata such as:
- Registration dates
- User IDs and usernames
- Bio information and associated URLs
- Geographical and time zone settings
- Display names, both current and those from 2021
- Follower counts from 2021 and 2025
- Total tweet counts and timestamps of the most recent tweets
- Platforms used for tweeting (like TweetDeck or the X Web App)
- Account status markers (verified or protected)
Notably, while the January 2023 breach contained email addresses, the 2025 data dump does not include this sensitive information. However, merging both breaches offers a fuller picture of user profiles. The datasets are formatted as CSV files, resembling data outputs typically extracted using API tools such as Tweepy.
Additional analysis by Cyber Press uncovered 165 related files, including several compressed CSV files dated January 24, 2025, each ranging from 361MB to 376MB in size.
Implications and Uncertainties
The sheer volume of the breach is striking. With X reporting around 335.7 million active users as of January 2025, the claim of 2.87 billion records suggests that the dataset might also include archived, deleted, or inactive accounts. As of April 1, 2025, X has not issued an official statement regarding the incident, leaving the extent of the exposure and its potential ramifications uncertain.
If confirmed, this breach would rank as the second-largest in history, surpassed only by the National Public Data incident, which involved 3.1 billion records. For users of X, the exposure of such comprehensive profile details could significantly heighten the risk of targeted phishing and identity impersonation, even though direct email disclosures were not part of the latest leak.




