01Summary
The breach exploited an API vulnerability in Snapchat's 'Find Friends' feature, which allowed attackers to submit large batches of phone numbers and match them against Snapchat usernames. Approximately 4.6 million username-phone number pairings were scraped and subsequently posted on a website called SnapchatDB. The attackers partially redacted the data but made it available for download. The incident came just weeks after security researchers had warned Snapchat about the vulnerability. Snapchat later released an update to mitigate the issue. The breach raised significant privacy concerns about the handling of personal data by social media platforms.
02Background
Snapchat was a rapidly growing social media platform in 2014, particularly popular among younger users. The platform's 'Find Friends' feature was designed to help users connect with contacts from their phone's address book.
03Key revelations
- 01Snapchat's 'Find Friends' API lacked basic rate limiting protections.
- 02Security researchers had warned Snapchat about the vulnerability weeks prior.
- 034.6 million users' phone numbers were publicly exposed.
04Technical analysis
The attack exploited the lack of rate limiting in Snapchat's API. By submitting batches of phone numbers, attackers could query the API to check which numbers were associated with Snapchat accounts and collect the corresponding usernames.
- Attack vector
- API abuse (lack of rate limiting)
- Attack method
- Data scraping via public API
- Initial access
- Public API abuse
- Exfiltration
- Data scraping via API
Vulnerabilities exploited
- Lack of API rate limiting
05Threat actor
The perpetrator remains unknown. The attack was relatively unsophisticated, exploiting a lack of API rate limiting rather than a complex technical vulnerability.
Attribution sources
- Media Reports
- Security Researchers
06Victims and impact
Countries affected
- United States
- Global
07Data exposed
Data types
- Usernames
- Phone Numbers
Notable documents
- SnapchatDB (leaked database)
08Financial damage
Reputational damage and loss of user trust.
09Timeline
- 2013-12-31Attackers scrape 4.6M Snapchat usernames and phone numbers via public API.
- 2014-01-01Leaked data published as 'SnapchatDB.'
10Reaction and fallout
Public reaction
Widespread concern about Snapchat's security practices and questions about data retention policies.
Political impact
The incident contributed to broader discussions about API security and user privacy protections on social media platforms.
11Legal
The FTC investigated Snapchat's security practices, leading to a 20-year consent decree.
Civil lawsuits
- FTC complaint and settlement
12Aftermath
Policy changes
- Improved API rate limiting and security practices across the industry.
Security improvements
- Snapchat implemented rate limiting on its API.
- Enhanced user privacy controls.
13Significance and legacy
Significance
The Snappening highlighted the risks of insufficient API security and set a precedent for user phone number protection on social platforms.
Legacy
The incident contributed to the broader movement toward stricter API security standards and rate limiting across the tech industry.
14Disclosure and media
- Authentication
- Media verification of leaked data
Publishing organisations
- SnapchatDB
15Field notes
- 01Security researchers at Gibson Security had warned Snapchat about this exact vulnerability weeks before the breach.
- 02The breach was dubbed the 'Snappening' by media outlets.
16Resolution
Snapchat released an update to address the vulnerability and agreed to 20 years of FTC monitoring.
17Sources
Official documents
- FTC consent decree with Snapchat
References
- [1]Media reports (The Verge, TechCrunch, 2014)
- [2]FTC filing









