What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
In January 2023, SecurityWeek reported that Hudson Rock had warned of a database containing more than 235 million unique Twitter-user records circulating online for free. The records reportedly included names, usernames, email addresses, follower counts and account creation dates. That was a contemporaneous report—not an independently audited count—and it does not establish that the database remains available today or that every record represented a confirmed victim.
What was in the reported 235 million Twitter records database?
SecurityWeek’s January 5, 2023 report said Hudson Rock had identified a database with over 235 million unique records. The listed fields were names, usernames, email addresses, follower counts and account creation dates. The figure and field list reflect what was reported at the time; they were not independently audited in the source reviewed here. SecurityWeek’s report described the records as available free online then.
The report said the records appeared to have been gathered through web scraping. Ron Scott-Adams of HCI & Data Cloud assessed that the data appeared to be at least two years old and mostly public information, apart from the email addresses. Those are attributed assessments, not independently verified findings about how the database was assembled or when each record was collected.
Free tools Windows power users keep installed
One-click scans. No signup required.
The report also contrasted this database with an earlier, separate dataset of 5.4 million users that was offered for sale in 2022 for a reported $30,000. Those figures were likewise reported by SecurityWeek and should not be combined with the later 235-million-record claim.
#1 Best Overall
Was my email address exposed?
The available reporting cannot determine whether a particular person’s email address was in the database. A reported total of unique records is not a verified count of people whose information was confirmed exposed, and the report does not provide a way to check an individual record reliably. It also does not establish the database’s current location, operator, accessibility or removal status. Its “available for free” description applies to the 2023 report, not necessarily to October 2026.
Hudson Rock co-founder and CTO Alon Gal warned that the records could contribute to hacking, targeted phishing and doxxing. That was a risk assessment, not evidence that everyone represented in the data was attacked. Treat unexpected messages claiming to know your email or Twitter identity cautiously, and avoid searching for or downloading a purported copy: doing so is not a safe or reliable way to establish whether your details were included.
Was the database the same as Twitter’s contact-discovery vulnerability?
No connection between the 235-million-record database and the vulnerability has been demonstrated by the cited reporting. They are related privacy episodes, but the evidence describes them separately.
| Question | 235-million-record database report | Contact-discovery vulnerability |
|---|---|---|
| Timing | Reported as circulating free online in January 2023. | Introduced in a June 2021 software update; Twitter said it fixed the bug in January 2022. |
| Information described | Names, usernames, email addresses, follower counts and account creation dates. | Whether an email address or phone number was associated with a Twitter account, including where the contact details were meant to be private. |
| What is established | Scraping was an attributed assessment; the dataset’s provenance was not independently verified in the cited report. | Twitter acknowledged exploitation, said the impact was global, and said it could not determine the total number of affected accounts. |
| Relationship | The reporting does not establish that the database resulted from the vulnerability. | Relevant context, but not proof of the 235-million-record dataset’s source. |
The Associated Press, in a report carried by SecurityWeek on August 6, 2022, quoted Twitter as saying passwords were not exposed in the acknowledged vulnerability. That statement concerns that specific incident; it does not establish what may or may not have been present in unrelated datasets. Twitter also said it could not determine exactly how many accounts were affected or where their holders were located. The report on the contact-discovery incident noted Twitter’s regret about the risks to pseudonymous account holders.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to secure your X account now
X’s account-security guidance recommends a strong, unique password, two-factor authentication (2FA), and caution with suspicious links. These measures help protect future account access; they cannot retrieve, delete or reverse copies of information that may already have circulated.
- Use a unique password. Choose a strong password not used on another service. A password manager can help you create and maintain unique credentials.
- Enable two-factor authentication. In X, open Settings and privacy → Security and account access → Security → Two-factor authentication, then choose an available method. X documents physical security keys and authentication apps among its options. Availability of app or SMS methods can vary by account type, country and carrier.
- Keep recovery access available. Before changing authentication settings, make sure you can still access the recovery options associated with your account. Follow the current prompts in X, as available options and labels can change.
- Check links before entering credentials. Be wary of unexpected messages that urge you to sign in. Verify that the address bar shows X’s legitimate domain before entering your password or authentication code.
X’s official two-factor authentication guidance and account-security tips explain its current recommendations. A physical security key is an optional way to strengthen sign-in, not a remedy for historic exposure.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

