EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/snapchat-snappening-2014
301/430

File EL-0130HighResolvedData Breach / Credential Theft

Snapchat 'Snappening' Data Leak (2014)

Also filed as Snapchat User Data Breach · SnapchatDB

In January 2014, attackers scraped and leaked usernames and phone numbers of approximately 4.6 million Snapchat users. The breach exposed vulnerabilities in Snapchat's 'Find Friends' API, which could be abused to rapidly enumerate user accounts and harvest phone numbers.

  • #snapchat
  • #data-breach
  • #credential-theft
  • #pii
  • #2014
  • #social-media
Notoriety7/10
Event
1 Jan 2014
Disclosed
1 Jan 2014
Target
Snapchat
Scale
4.6M people
Status
Resolved

01Summary

The breach exploited an API vulnerability in Snapchat's 'Find Friends' feature, which allowed attackers to submit large batches of phone numbers and match them against Snapchat usernames. Approximately 4.6 million username-phone number pairings were scraped and subsequently posted on a website called SnapchatDB. The attackers partially redacted the data but made it available for download. The incident came just weeks after security researchers had warned Snapchat about the vulnerability. Snapchat later released an update to mitigate the issue. The breach raised significant privacy concerns about the handling of personal data by social media platforms.

02Background

Snapchat was a rapidly growing social media platform in 2014, particularly popular among younger users. The platform's 'Find Friends' feature was designed to help users connect with contacts from their phone's address book.

03Key revelations

  1. 01Snapchat's 'Find Friends' API lacked basic rate limiting protections.
  2. 02Security researchers had warned Snapchat about the vulnerability weeks prior.
  3. 034.6 million users' phone numbers were publicly exposed.

04Technical analysis

The attack exploited the lack of rate limiting in Snapchat's API. By submitting batches of phone numbers, attackers could query the API to check which numbers were associated with Snapchat accounts and collect the corresponding usernames.

Attack vector
API abuse (lack of rate limiting)
Attack method
Data scraping via public API
Initial access
Public API abuse
Exfiltration
Data scraping via API

Vulnerabilities exploited

  • Lack of API rate limiting

05Threat actor

The perpetrator remains unknown. The attack was relatively unsophisticated, exploiting a lack of API rate limiting rather than a complex technical vulnerability.

Attribution sources

  • Media Reports
  • Security Researchers

06Victims and impact

Countries affected

  • United States
  • Global

07Data exposed

Data types

  • Usernames
  • Phone Numbers

Notable documents

  • SnapchatDB (leaked database)

08Financial damage

Reputational damage and loss of user trust.

09Timeline

  1. 2013-12-31Attackers scrape 4.6M Snapchat usernames and phone numbers via public API.
  2. 2014-01-01Leaked data published as 'SnapchatDB.'

10Reaction and fallout

Public reaction

Widespread concern about Snapchat's security practices and questions about data retention policies.

Political impact

The incident contributed to broader discussions about API security and user privacy protections on social media platforms.

11Legal

The FTC investigated Snapchat's security practices, leading to a 20-year consent decree.

Civil lawsuits

  • FTC complaint and settlement

12Aftermath

Policy changes

  • Improved API rate limiting and security practices across the industry.

Security improvements

  • Snapchat implemented rate limiting on its API.
  • Enhanced user privacy controls.

13Significance and legacy

Significance

The Snappening highlighted the risks of insufficient API security and set a precedent for user phone number protection on social platforms.

Legacy

The incident contributed to the broader movement toward stricter API security standards and rate limiting across the tech industry.

14Disclosure and media

Authentication
Media verification of leaked data

Publishing organisations

  • SnapchatDB

15Field notes

  1. 01Security researchers at Gibson Security had warned Snapchat about this exact vulnerability weeks before the breach.
  2. 02The breach was dubbed the 'Snappening' by media outlets.

16Resolution

Snapchat released an update to address the vulnerability and agreed to 20 years of FTC monitoring.

17Sources

Official documents

  • FTC consent decree with Snapchat

References

  1. [1]Media reports (The Verge, TechCrunch, 2014)
  2. [2]FTC filing
Fact sheetEL-0130

Dates

Event
1 Jan 2014
Started
31 Dec 2013
Ended
1 Jan 2014
Duration
10 days
Discovered
1 Jan 2014
Disclosed
1 Jan 2014
Resolved
10 Jan 2014
Ongoing
No

Target

Organisation
Snapchat Inc.
Type
Corporation
Sector
Social Media / Technology
Country
United States

Actor

Motivation
Unknown; likely notoriety or data monetization.
Attribution
Low
Arrested
No
Convicted
No

Data

People
4,600,000
Records
4,600,000
Volume
4.6 million records
Sensitivity
Confidential
Published
Yes
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.