Our Analysts Found 13.6 Million Twitter Passwords Stored in Plain Text
HEROIC analysts identified 13,668,204 exposed records tied to a Twitter data breach dated August 31, 2015. This is by far the largest of the Twitter related incidents in our database, exposing email addresses and passwords stored in plaintext for well over 13 million accounts.
Why 13.6 Million Plaintext Passwords From Twitter Is a Major Risk
Scale changes everything about a breach like this. When a database of this size is stored with plaintext passwords, meaning the passwords were never hashed or encrypted, every single record becomes instantly usable by anyone who obtains the data. There is no cracking involved, no guessing, no delay. An attacker with this file has over 13 million ready made email and password combinations they can try immediately on Twitter and on any other site where those same credentials might have been reused.
What Was Exposed
- Email addresses
- Passwords stored in plaintext
Why This Matters
A breach of this size, combined with plaintext passwords, is exactly the kind of dataset that fuels large scale credential stuffing campaigns. Attackers load lists like this into automated tools that test each email and password pair against banking sites, email providers, and other social platforms in bulk. Because so many people reuse the same password across multiple accounts, a single leaked Twitter password can lead directly to account takeover, identity theft, or financial fraud on services that have nothing to do with Twitter at all.
How a Database Breach Exposes Millions of Records at Once
This incident is classified as a database breach, meaning attackers obtained the data directly from stored records rather than through malware on individual devices. Breaches of this scale typically happen when attackers exploit a vulnerability in how a system is built, gain access through compromised administrator credentials, or discover a server that was left insufficiently protected. Storing passwords in plaintext removes the one safeguard that normally limits the damage of a breach like this, since properly hashed passwords would have required attackers to crack each one individually rather than use them immediately.
Check If You Are Affected
With more than 13 million accounts involved, the odds that your information is part of this breach are meaningfully higher than in a smaller leak. HEROIC's free breach scanner searches more than 400 billion leaked records to show you whether your email address and password have surfaced in this Twitter breach or any other known incident. Run a free scan today and change any passwords you may have reused elsewhere.
Breach Breakdown
13,668,204 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds