Hackers post email addresses linked to 200 million Twitter accounts, security researchers say | CNN Business (2024)

Hackers post email addresses linked to 200 million Twitter accounts, security researchers say | CNN Business (1)

Video Ad Feedback

Twitter users vote to remove Elon Musk as head of platform

03:39 - Source: CNN

CNN

Email addresses linked to more than 200 million Twitter profiles are currently circulating on underground hacker forums, security experts say. The apparent data leak could expose the real-life identities of anonymous Twitter users and make it easier for criminals to hijack Twitter accounts, the experts warned, or even victims’ accounts on other websites.

The trove of leaked records also includes Twitter users’ names, account handles, follower numbers and the dates the accounts were created, according to forum listings reviewed by security researchers and shared with CNN.

“Bad actors have won the jackpot,” said Rafi Mendelsohn, a spokesman for Cyabra, a social media analysis firm focused on identifying disinformation and inauthentic online behavior. “Previously private data such as emails, handles, and creation date can be leveraged to build smarter and more sophisticated hacking, phishing and disinformation campaigns.”

Some reports suggested the data was collected in 2021 through a bug in Twitter’s systems, a flaw the company fixed in 2022 after a separate incident in July involving 5.4 million Twitter accounts alerted the company to the vulnerability.

A view of the Twitter logo at its corporate headquarters in San Francisco, California, U.S. October 28, 2022. REUTERS/Carlos Barria Carlos Barria/Reuters With its advertising business in crisis, Twitter eases ban on political ads

Troy Hunt, a security researcher, said Thursday that his analysis of the data “found 211,524,284 unique email addresses” that had been leaked. The Washington Post earlier reported a forum listing promoting the data of 235 million accounts.

Hunt did not immediately respond to a question from CNN asking whether the records would be added to his website, haveibeenpwned.com, which allows users to search hacked records to determine if they have been affected. CNN has not independently verified the records’ authenticity.

Twitter didn’t immediately respond to a request for comment. Its communication team, along with roughly half of Twitter’s overall workforce, was gutted after billionaire Elon Musk completed his acquisition the company in late October. The significant staff reductions could now add to concerns about the company’s ability to respond to security threats.

The breadth of the leaked data could allow malicious actors or repressive governments to connect anonymous Twitter handles with the real names or email addresses of their owners, potentially unmasking dissidents, journalists, activists or other at-risk users around the world, security researchers warn.

“For those people, this is a very consequential breach,” said John Scott-Railton, a security researcher at The University of Toronto’s Citizen Lab.

The account data could also be valuable to hackers who can use the information as part of password-reset attempts and account takeovers. The risk is particularly high for individuals who use the same account credentials on Twitter as they do for other digital services such as banks or cloud storage, researchers said, because hackers could take information gleaned from the leak to pry open user accounts elsewhere.

Verified Twitter users caught up in the apparent leak, or users with particularly large followings, will be particularly valuable targets as a result of the leak, security experts warned, as those account holders may be especially influential celebrities or susceptible to extortion.

To protect themselves from phishing attempts, internet users should use unique passwords for each online service and keep track of them using a digital password manager, security researchers say. They should also enable multi-factor authentication for each of their accounts, and exercise caution when opening unsolicited email or links.

According to the cybersecurity news outlet BleepingComputer, which did claim to test the data, the latest dump appears similar to a leaked dataset advertised on hacking forums in November containing an alleged 400 million records, but slimmed down to eliminate some duplicate records. Twitter has not commented on that leak.

Reports of the leak could expand Twitter’s already significant legal and regulatory risk.

In December, Twitter’s main European privacy regulator, the Irish Data Protection Commission, said it is investigating the July 2022 leak as a possible violation of Europe’s signature privacy law, known as GDPR.

Last summer, the company’s former head of security, Peiter “Mudge” Zatko, filed a whistleblower report to the US government alleging long-ignored security vulnerabilities in Twitter’s operations. Zatko claimed that Twitter’s shortcomings on security reflected a breach of Twitter’s binding commitments to the Federal Trade Commission, a serious offense. (Twitter broadly and repeatedly pushed back at Zatko’s allegations.)

Successive incidents at Twitter have led to the company signing two consent orders with the FTC since 2011 to improve its cybersecurity posture. Violations of FTC orders can lead to fines, business restrictions and even sanctions targeting individual executives.

In November, top Twitter officials responsible for privacy and security resigned from the company, just days after Musk closed his purchase of the platform and amid the mass layoffs that in some cases cut whole departments.

Hackers post email addresses linked to 200 million Twitter accounts, security researchers say | CNN Business (2024)

FAQs

Hackers post email addresses linked to 200 million Twitter accounts, security researchers say | CNN Business? ›

Hackers post email addresses linked to 200 million Twitter accounts, security researchers say. Email addresses linked to more than 200 million Twitter profiles are currently circulating on underground hacker forums, security experts say.

What does Twitter's 200 million user email leak actually mean? ›

And while the bug didn't allow hackers to access passwords or other sensitive information like DMs, it did expose the connection between Twitter accounts, which are often pseudonymous, and the email addresses and phone numbers linked to them, potentially identifying users.

How do hackers get into Twitter accounts? ›

Twitter hacks can occur when hackers acquire your personal information via data breaches or phishing, but they can also be the result of malware or brute force attacks.

What is the Twitter email data breach? ›

How was Twitter hacked? Hackers exploited an API vulnerability to gain unauthorized access to Twitter's user data, matching email addresses with profiles. This security flaw persisted from June 2021 to January 2022, ultimately leading to the exposure of email addresses, names, and usernames for millions of users.

Who hacked all the Twitter accounts? ›

A third individual, Graham Ivan Clark, 17 years old, of Hillsborough County, Florida, was also indicted; the charges were originally sealed in juvenile court, but he was eventually charged as an adult on 30 felony counts. The charges included organized fraud, communications fraud, identity theft, and hacking.

What happens if your email is leaked? ›

Phishing Attempts: Scammers may target you with phishing emails, trying to trick you into revealing sensitive information. Cybercrime: In severe cases, attackers might use your leaked email address to access your accounts, potentially taking control of them.

Can someone see my email on Twitter? ›

Twitter allows users to discover other users' profiles using their email address or phone number. However, users can turn off these permissions to prevent people from finding their Twitter profile through those methods.

How do you know if your Twitter account has been hacked? ›

Noticed unexpected posts by your account. Seen unintended Direct Messages sent from your account. Observed other account behaviors you didn't make or approve (like following, unfollowing, or blocking)

How did my email get breached? ›

Your computer was most likely compromised in one of four ways: You do not have up-to-date security software installed. Your passwords are weak and easily hacked. You clicked on a malicious link in an email, IM conversation, or on a social networking site, or webpage.

Can I sue Twitter for data breach? ›

When data protection standards have fallen short, and in this case a hack has enabled unauthorised access to your personal data, you can make a claim for compensation. Bringing a data breach claim not only gets you access to compensation, but also holds a company or organisation to account for their actions.

Who stalks my Twitter account? ›

Twitter doesn't tell you who viewed your Twitter profile. The microblogging platform doesn't provide this information to protect user privacy. The only profile view metric you can see is the number of visits to your profile.

What are the most hacked accounts? ›

Facebook accounts are the most hacked accounts on the internet in the United States, according to new research by VPN Central.

Can you report a Twitter account for being hacked? ›

If your account was compromised and you cannot get in, use the Twitter “password reset form” to try and regain access. If that does not work you will need to contact their support team ASAP. You can report impersonation accounts, spam, fake Twitter emails, private information and other abusive behaviors on Twitter.

What is leaked on Twitter? ›

The leaked data includes email addresses, names, and Twitter account details, leaving users vulnerable to phishing attacks, identity theft, and social engineering schemes.

What is the Twitter user data breach? ›

Data collection sale was started on 4th December 2023 containing more than 200 million Twitter profiles. The breached data was released as a 59 GB RAR archive. The vulnerable API was compromised by the scrapers using earlier data collections. Twitter users should be aware of targeted phishing scam campaigns.

How does Twitter decide what to email you? ›

The algorithm's goal is to show people content that matches their interests, preferences and behavior on the platform. To figure out what's relevant, Twitter (X's) algorithm looks at a bunch of signals, like who you follow and the topics you like to interact with.

Why am I getting emails from Twitter? ›

For instance, they can receive an email each time they receive a direct message on Twitter. Users have the option to turn off email notifications if they don't want to receive these kinds of alerts.

Top Articles
Latest Posts
Article information

Author: Twana Towne Ret

Last Updated:

Views: 6357

Rating: 4.3 / 5 (44 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Twana Towne Ret

Birthday: 1994-03-19

Address: Apt. 990 97439 Corwin Motorway, Port Eliseoburgh, NM 99144-2618

Phone: +5958753152963

Job: National Specialist

Hobby: Kayaking, Photography, Skydiving, Embroidery, Leather crafting, Orienteering, Cooking

Introduction: My name is Twana Towne Ret, I am a famous, talented, joyous, perfect, powerful, inquisitive, lovely person who loves writing and wants to share my knowledge and understanding with you.