THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Saturday, December 03, 2022
A summer data breach at Twitter saw hackers publish stolen data, but an even bigger data breach has since been uncovered
FREMONT, CA: After stolen data was made public online, a data hack that affected Twitter last summer has returned to haunt Elon Musk's platform. Twitter was compromised in July of this year due to a flaw that has been present since late 2021.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
On the hacker forum Breached Forums, the hacker who went under the username devil started advertising the 5.4 million user Twitter database for USD 30,000 in the summer.
User Data
After a data breach exposed the personal information of more than one billion Chinese citizens in July 2022, the hacker site breached forums attracted attention worldwide. Even if the user had disabled these fields in the privacy settings, the Twitter vulnerability allowed the devil to obtain Twitter IDs, names, login names, locations, and verified statuses. It also included private information, such as phone numbers and email addresses.
According to reports, the fault happened with Twitter's API and was exclusive to the Android client for Twitter. In January 2022, Twitter had already patched the vulnerability.
In less than five months, BleepingComputer revealed on Monday that 5.4 million user records containing passwords, phone numbers, emails, and other information had been freely distributed on a hacker forum.
Last weekend, the proprietor of the hacking forum Breached revealed to BleepingComputer that they were in charge of exploiting the flaw and producing the enormous dump of Twitter user details after Devil had disclosed the vulnerability to them.
A total of nearly 7 million Twitter profiles containing sensitive information were exposed, according to BleepingComputer, including the 5.4 million records for sale and an additional 1.4 million suspended user profiles that were gathered through a different API.
The second data dump was privately distributed to a few persons and was not sold.
Second Breach
A bigger data dump is purportedly made using the same vulnerability, according to a claim by BleepingComputer, making the fact that hackers gave away 5.4 million records good news.
According to BleepingComputer, security expert Chad Loder, who first broke the story on Twitter and was removed shortly after publishing it, was the source of information about this more serious data leak.
Following Elon Musk's takeover of Twitter, Loder shared a redacted excerpt of this broader data breach on Mastodon, a social media platform that many Twitter users are now using instead.
A significant Twitter data breach affected millions of US and EU Twitter accounts. No sooner than 2021 did this breach occur, said Loder on Twitter. They got in touch with many affected accounts and confirmed that the stolen information was accurate. A sample file from this previously unknown Twitter data dump was obtained by BleepingComputer, containing 1,377,132 phone numbers for French users. Many users involved in this data leak have confirmed the validity of the phone numbers.
More in News