Hackers post email addresses linked to 200 million Twitter accounts, security researchers say | CNN Business (2024)

Hackers post email addresses linked to 200 million Twitter accounts, security researchers say | CNN Business (1)

Twitter users vote to remove Elon Musk as head of platform

03:39 - Source: CNN

CNN

Email addresses linked to more than 200 million Twitter profiles are currently circulating on underground hacker forums, security experts say. The apparent data leak could expose the real-life identities of anonymous Twitter users and make it easier for criminals to hijack Twitter accounts, the experts warned, or even victims’ accounts on other websites.

The trove of leaked records also includes Twitter users’ names, account handles, follower numbers and the dates the accounts were created, according to forum listings reviewed by security researchers and shared with CNN.

“Bad actors have won the jackpot,” said Rafi Mendelsohn, a spokesman for Cyabra, a social media analysis firm focused on identifying disinformation and inauthentic online behavior. “Previously private data such as emails, handles, and creation date can be leveraged to build smarter and more sophisticated hacking, phishing and disinformation campaigns.”

Some reports suggested the data was collected in 2021 through a bug in Twitter’s systems, a flaw the company fixed in 2022 after a separate incident in July involving 5.4 million Twitter accounts alerted the company to the vulnerability.

A view of the Twitter logo at its corporate headquarters in San Francisco, California, U.S. October 28, 2022. REUTERS/Carlos Barria Carlos Barria/Reuters With its advertising business in crisis, Twitter eases ban on political ads

Troy Hunt, a security researcher, said Thursday that his analysis of the data “found 211,524,284 unique email addresses” that had been leaked. The Washington Post earlier reported a forum listing promoting the data of 235 million accounts.

Hunt did not immediately respond to a question from CNN asking whether the records would be added to his website, haveibeenpwned.com, which allows users to search hacked records to determine if they have been affected. CNN has not independently verified the records’ authenticity.

Twitter didn’t immediately respond to a request for comment. Its communication team, along with roughly half of Twitter’s overall workforce, was gutted after billionaire Elon Musk completed his acquisition the company in late October. The significant staff reductions could now add to concerns about the company’s ability to respond to security threats.

The breadth of the leaked data could allow malicious actors or repressive governments to connect anonymous Twitter handles with the real names or email addresses of their owners, potentially unmasking dissidents, journalists, activists or other at-risk users around the world, security researchers warn.

“For those people, this is a very consequential breach,” said John Scott-Railton, a security researcher at The University of Toronto’s Citizen Lab.

The account data could also be valuable to hackers who can use the information as part of password-reset attempts and account takeovers. The risk is particularly high for individuals who use the same account credentials on Twitter as they do for other digital services such as banks or cloud storage, researchers said, because hackers could take information gleaned from the leak to pry open user accounts elsewhere.

Verified Twitter users caught up in the apparent leak, or users with particularly large followings, will be particularly valuable targets as a result of the leak, security experts warned, as those account holders may be especially influential celebrities or susceptible to extortion.

To protect themselves from phishing attempts, internet users should use unique passwords for each online service and keep track of them using a digital password manager, security researchers say. They should also enable multi-factor authentication for each of their accounts, and exercise caution when opening unsolicited email or links.

According to the cybersecurity news outlet BleepingComputer, which did claim to test the data, the latest dump appears similar to a leaked dataset advertised on hacking forums in November containing an alleged 400 million records, but slimmed down to eliminate some duplicate records. Twitter has not commented on that leak.

Reports of the leak could expand Twitter’s already significant legal and regulatory risk.

In December, Twitter’s main European privacy regulator, the Irish Data Protection Commission, said it is investigating the July 2022 leak as a possible violation of Europe’s signature privacy law, known as GDPR.

Last summer, the company’s former head of security, Peiter “Mudge” Zatko, filed a whistleblower report to the US government alleging long-ignored security vulnerabilities in Twitter’s operations. Zatko claimed that Twitter’s shortcomings on security reflected a breach of Twitter’s binding commitments to the Federal Trade Commission, a serious offense. (Twitter broadly and repeatedly pushed back at Zatko’s allegations.)

Successive incidents at Twitter have led to the company signing two consent orders with the FTC since 2011 to improve its cybersecurity posture. Violations of FTC orders can lead to fines, business restrictions and even sanctions targeting individual executives.

In November, top Twitter officials responsible for privacy and security resigned from the company, just days after Musk closed his purchase of the platform and amid the mass layoffs that in some cases cut whole departments.

Hackers post email addresses linked to 200 million Twitter accounts, security researchers say | CNN Business (2024)

References

Top Articles
Top CD Rates Today, June 18, 2024 - Earn a Guaranteed 6.00% Until Next April
Best 10-Year CD Rates for June 2024
Scammer phone number lookup. How to check if a phone number is a scam
Buenasado Bluewater
Round Yellow Adderall
Pierced Universe Coupon
Paulette Goddard | American Actress, Modern Times, Charlie Chaplin
Xfinity Store By Comcast Branded Partner Fort Gratiot Township Photos
Cdn Bustednewspaper
Craigslist Org Hattiesburg Ms
Unblocked WTF, UBG9 Unblocked Games, UBGWTF Games, Unblocked WTF, WTF Games Unblocked
Breakroom Bw
Ixl Spring Branch
Nu Do Society Menu
Elanco Rebates.com 2022
Open jazz : podcast et émission en replay | France Musique
Dumb Money Showtimes Near Regal Edwards Nampa Spectrum
The Legend of Zelda: Every Reincarnation of Princess Zelda Explained
Sunset On November 5 2023
Neos Urgent Care Springfield Ma
Paying Cash for Comics, Sports Cards, Collections, Honest - Respectful - wanted - by dealer - sale - craigslist
27 Sage Street Holmdel Nj
Usc Human Biology
Handshoe's Flea Market & Salvage Llc Photos
Roundpoint Mortgage Mortgagee Clause
How To Get Genji Cute Spray
Peloton Guide Stuck Installing Update
Owyhee County Extension Office
Lil Coffea Shop 6Th Ave Photos
Hewn New Bedford
Poskes Parts
Gmc For Sale Craigslist
Cece Rose Facial
Assume The Slave Position Natashas Bedroom
Theatervoorstellingen in Roosendaal, het complete aanbod.
Ella And David Steve Strange
Www.1Tamilmv.cfd
Dicks: The Musical Showtimes Near Regal Galleria Mall
Giant Egg Classic Wow
Depths Charm Calamity
Craigslist Cars For Sale By Owner Memphis Tn
New York Rangers Hfboards
Makes A Successful Catch Maybe Crossword Clue
Wash World Of Lexington Coin Laundry
The forgotten history of cats in the navy
Katopunk Pegging
Craigslist For Pets For Sale
Delta Rastrear Vuelo
Mexican cartel leader 'El Mayo' Zambada pleads not guilty to US charges
Eliza Hay, MBA on LinkedIn: I’m happy to share that I’ve started a new position as Regional Director… | 36 comments
Vorschau: Battle for Azeroth – eine Tour durch Drustvar
The Complete History Of The Yahoo Logo - Hatchwise
Latest Posts
Article information

Author: Virgilio Hermann JD

Last Updated:

Views: 6712

Rating: 4 / 5 (61 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Virgilio Hermann JD

Birthday: 1997-12-21

Address: 6946 Schoen Cove, Sipesshire, MO 55944

Phone: +3763365785260

Job: Accounting Engineer

Hobby: Web surfing, Rafting, Dowsing, Stand-up comedy, Ghost hunting, Swimming, Amateur radio

Introduction: My name is Virgilio Hermann JD, I am a fine, gifted, beautiful, encouraging, kind, talented, zealous person who loves writing and wants to share my knowledge and understanding with you.