X Twitter Data Sharing Class Action Claims: What Consumers Should Know

X Corp faces an active class action over a 2021-2022 data breach affecting 200 million users—here's what you need to know about eligibility, status, and next steps.

X Corp (formerly Twitter) faces an ongoing federal class action lawsuit alleging that the company negligently exposed the personal information of approximately 200 million users through a security vulnerability that existed between June 2021 and January 2022. As of July 2026, the case has advanced past initial dismissal motions but has not yet reached a settlement, meaning consumers who were affected still have the opportunity to potentially participate in a future claim, though no payouts are currently available. A federal magistrate judge in the Northern District of California ruled in late 2024 that the case could proceed despite X’s arguments that its terms of service protected it from liability.

The breach exposed sensitive personal data including email addresses, phone numbers, usernames, display names, account creation dates, and location information. While passwords were not part of the exposed data, the combination of email addresses and phone numbers tied to account information created significant identity theft and fraud risks for affected users. Security researchers discovered that hackers exploited a flaw introduced in the platform’s source code to systematically scrape account information, with the stolen data eventually appearing for sale on hacking forums in July 2022.

Table of Contents

How Did the X/Twitter Data Exposure Happen?

Between June 2021 and January 2022, Twitter introduced a change to its application programming interface (API) that inadvertently allowed anyone with basic technical knowledge to look up Twitter accounts by entering an email address or phone number. This vulnerability was a direct result of code changes made in June 2021, meaning the company’s development team had created the security flaw themselves rather than being exploited through an external hack. A security researcher discovered the vulnerability and responsibly reported it through Twitter’s Bug Bounty Program in January 2022.

Twitter patched the flaw shortly after being notified. However, by that time, cybercriminals had already exploited the vulnerability to scrape data on millions of accounts. Security research later determined that at least 5.4 million accounts had been compromised, though the lawsuit claims the exposure affected closer to 200 million users. The criminal actors who exploited the vulnerability attempted to sell the stolen data on hacking forums for $30,000.

What Personal Information Was Exposed and What’s the Risk?

The exposed data included email addresses, phone numbers, usernames, display names, user bios, locations, and profile photos. The breach affected both active and suspended accounts, with researchers finding 6.7 million unique email addresses and 1.4 million phone numbers. Because email addresses and phone numbers are typically the primary contact information used for account recovery, identity verification, and password resets across the internet, this combination of data creates significant fraud risks.

One critical limitation of the lawsuit is timing: because the security flaw was patched in January 2022, long before Elon Musk purchased Twitter in October 2022, the case focuses on negligence rather than intentional data misuse. X has argued that even if the vulnerability existed, its terms of service limited liability for data security incidents. However, a federal judge rejected most of these liability-limitation arguments in December 2024, ruling that users could proceed with claims that Twitter knew about security inadequacies and made false statements about protecting user data. The company’s previous public statements about data security became key evidence in allowing the case to move forward.

Timeline of X/Twitter Data Breach and LitigationVulnerability Introduced320 DateVulnerability Exploited145 DateData Sold on Forum67 DateLawsuit Filed34 DateJudge Denies Dismissal12 DateSource: Northern District of California Court Records, Bloomberg Law, Media Post

What Is the Current Status of the Class Action Lawsuit?

As of July 2026, the Gerber v. X Corp class action is still in the litigation phase and has not reached a settlement. The case was brought by Stephen Gerber, a New York resident, and has since been joined by two additional named plaintiffs. The most recent court decision, issued in late 2024, allowed the majority of the plaintiffs’ claims to proceed to the next phase of litigation while tossing one claim (breach of contract) because the judge found that blog posts alone were insufficient to establish an express security contract.

The case remains in discovery and motion practice in the U.S. District Court for the Northern District of California. This means that legal teams are currently exchanging documents, deposing witnesses, and preparing for potential summary judgment motions. No trial date has been announced, and settlement discussions have not been publicly disclosed. For comparison, similar major data breach class actions typically take two to four years from the initial ruling to settlement, meaning consumers may need to wait until 2026 or 2027 for a potential resolution.

Who Is Eligible to Join This Class Action and How Do Claims Work?

To be eligible for the class action, you must have had a Twitter account during the vulnerability period of June 2021 through January 2022, and your account information must have been accessed by the cybercriminals who exploited the vulnerability. Since X has not publicly released a definitive list of affected accounts, and since many compromised account holders may not even be aware their data was breached, eligibility may eventually be determined through claims process documentation or evidence presented by the defendants.

This creates a practical challenge: unlike some settled class actions where companies automatically send notices to affected consumers, consumers in the Gerber case must currently monitor legal websites or news sources for updates about the case’s progress. When and if a settlement is eventually reached, a claims administrator will likely be appointed to receive and process claims from class members. The specific process—whether proof of account ownership will be required, whether a claim form will be simple or complex, and what documentation will be needed—cannot yet be determined because no settlement terms exist.

What Compensation Might Be Available and What Are the Limitations?

While no settlement amount has been announced, consumer compensation in data breach class actions typically ranges from $50 to $500 per person, depending on the size of the settlement fund, the number of eligible class members, and the estimated harm. Given that 200 million accounts were potentially affected, any settlement fund will likely be divided among a very large class, which typically results in smaller per-person payouts. For example, if a hypothetical $50 million settlement were reached and divided among 200 million users, each person would receive approximately $0.25—less than a quarter.

A significant limitation is that compensation in data breach cases is generally capped at actual documented losses or statutory damages, not punitive damages. This means that unless you can prove you suffered specific identity theft or fraud as a direct result of the Twitter data breach, your recovery may be limited to a court-approved statutory damage award, which is typically modest. Additionally, the presence of the earlier FTC settlement of $150 million (which addressed a separate issue of Twitter misusing phone numbers and email addresses collected for account security) means that X has already paid substantial penalties for data misuse, which may affect the court’s willingness to impose larger damages in the class action.

Earlier FTC Settlement and How It Differs from the Current Lawsuit

In May 2022, Twitter agreed to pay $150 million to the Federal Trade Commission and Department of Justice to settle charges that the company had deceptively used phone numbers and email addresses collected for account security purposes to target users with advertisements. This settlement required Twitter to cease using security contact information for advertising, implement enhanced security measures, and notify affected users about the violation.

However, this FTC enforcement action was distinct from the data breach class action because it focused on intentional misuse rather than negligence and a security flaw. The FTC settlement also did not go to consumers—the $150 million penalty went to the federal government, not to affected users. Individual consumers did not file claims or receive compensation from the FTC settlement, whereas when the Gerber class action eventually settles, consumers will have the opportunity to submit claims for compensation directly from the settlement fund.

What Should Consumers Do Right Now?

If you had a Twitter account between June 2021 and January 2022, monitor your credit reports and bank accounts for unauthorized activity, even though the breach occurred years ago. Stolen email and phone number information can be used for phishing, account takeovers, and social engineering fraud, and criminals sometimes hold stolen data for months or years before using it. Consider placing a credit freeze with the major credit bureaus (Equifax, Experian, and TransUnion) and enabling two-factor authentication on all important accounts, especially those linked to the email address or phone number that may have been exposed in the Twitter breach.

To receive updates about the Gerber v. X Corp litigation and any future settlement, regularly check legal settlement tracking websites and consider signing up for case-specific notification services. When a settlement is finalized and a claims deadline is announced, you will likely need to submit a claim form within a specific timeframe to receive compensation. Keep records of any identity theft or fraud that occurred between 2021 and the present day that might be connected to the data breach, as this documentation could support a higher damage claim if you choose to file.


You Might Also Like