X Profile Data Leak

X Profile Data Leak Reportedly Exposes Details of 2.87 Billion Users: eDiscovery Trends

According to a report, a massive X profile data leak has surfaced on Breach Forums, exposing the details of 2.87 billion users.

The story by Hackread states that – according to a post by a user on the Breach Forums named ThinkingOne, the leak is the result of a disgruntled X employee who allegedly stole the data during a period of mass layoffs. No official response from the company as of yet.

The original post by ThinkingOne states that the data, around 400GB worth, was likely exfiltrated during messy layoffs at X. The poster claims that they tried contacting X through multiple methods but received no response.

Advertisement
Cloudficient

Frustrated with the lack of acknowledgment from X and the general public, they took matters into their own hands and decided to merge the newly leaked data with another infamous breach from January 2023.

That breach affected around 209 million users, exposing email addresses, display names and usernames (handles), followers count and account creation dates.

While the reported 2025 X profile data leak doesn’t contain email addresses, it does contain several other types of metadata.

However, as the article notes, there’s a problem with the reported number of 2.87 billion users: As of Jan 2025, X (formerly Twitter) had around 335.7 million users, so how is it possible that data from 2.8 billion users has been leaked? The article suggests that it could be because the dataset includes aggregated or historical data, such as bot accounts that were created and later banned, inactive or deleted accounts that still lingered in historical records, or old data that was merged with newer data, increasing the total number of records.

Advertisement
KLDiscovery

With the total being eight times the reported number of current users, it seems like a reach to me, and it’s possibly why the story hasn’t gained any traction beyond the Hackread article. We’ll see if that changes.

So, what do you think? Do you think it’s possible that the reported 2025 X profile data leak could affect 2.87 billion users? Please share any comments you might have or if you’d like to know more about a particular topic.

Image created using GPT-4’s Image Creator Powered by DALL-E, using the term “robots finding out their data has been breached”.

Disclaimer: The views represented herein are exclusively the views of the author, and do not necessarily represent the views held by my employer, my partners or my clients. eDiscovery Today is made available solely for educational purposes to provide general information about general eDiscovery principles and not to provide specific legal advice applicable to any particular circumstance. eDiscovery Today should not be used as a substitute for competent legal advice from a lawyer you have retained and who has agreed to represent you.


Discover more from eDiscovery Today by Doug Austin

Subscribe to get the latest posts sent to your email.

3 comments

  1. Given that especially social media data could contain political views/bias, location data, connections/subscriptions to certain individuals or organisations, I am increasingly concerned that this data will be AI processed to discriminate against certain groups of citizens & visitors: grant or refuse public services, subsidies/grants or visas & residency permits

    This is especially problematic regarding historic/legacy data. Views change. So do the views of people you‘re connected to.

    China has already implemented this as a part of their „social credit system“. Behave within the norms of the communist party and you get credits added: Better housing, a place at a university, a permit to register a car.
    If you don‘t behave in those narrow norms, you might get denied all that.

    If this data gets processed by autohorities in the US, one might still enjoy freedom of speech, but don‘t be surprised if you don‘t win that government project, don‘t get that job or get denied certain benefits that „loyal“ people have no problem getting.

    It is already done for visitors to the US. But I fear this is just one more step to behavioral analysis for citizens, down the road.

    https://apnews.com/article/social-media-immigration-applicants-handles-dhs-f67b480abebff7e451056be17572593d

  2. ThinkingOne here. Social media sites use the metric “Monthly Active Users” (MAU), which typically refers to the number of users that logged on in the previous month. That’s the metric used where you see 300M-600M for Twitter. Knowing about MAU, the number of accounts ever created is going to be much higher.

    Checking a representative sample of 100 users from the dataset (I’d do more, but feel it is necessary to do it by hand to avoid violating laws), 92% had both the user ID and screenname match what Twitter had (e.g. going to https://x.com/%5Bscreenname%5D). 100 isn’t much, but if the sample is indeed representative (and you can trust me), I’m sure a statistician would agree that it is impossible for Twitter to have less than 2B accounts. Half of the “bad” 8% were accounts that did not exist (likely deleted), the other half either had a valid screenname or valid user ID (e.g. suspended accounts, or people changing the screenname).

Leave a Reply