In January 2014 just one week after Gibson Security detailed vulnerabilities in the service, Snapchat had 4.6 million usernames and phone number exposed. The attack involved brute force enumeration of a large number of phone numbers against the Snapchat API in what appears to be a response to Snapchat’s assertion that such an attack was "theoretical". Consequently, the breach enabled individual usernames (which are often used across other services) to be resolved to phone numbers which users usually wish to keep private.
Accounts breached: 4609615
Breached on: January 01, 2014
Exposed data: Geographic locations, Phone numbers, and Usernames
Domain: snapchat.com
Added on: January 02, 2014