Hackers post email addresses linked to 200 million Twitter accounts, security researchers say | CNN Business (2024)

Hackers post email addresses linked to 200 million Twitter accounts, security researchers say | CNN Business (1)

Twitter users vote to remove Elon Musk as head of platform

03:39 - Source: CNN

CNN

Email addresses linked to more than 200 million Twitter profiles are currently circulating on underground hacker forums, security experts say. The apparent data leak could expose the real-life identities of anonymous Twitter users and make it easier for criminals to hijack Twitter accounts, the experts warned, or even victims’ accounts on other websites.

The trove of leaked records also includes Twitter users’ names, account handles, follower numbers and the dates the accounts were created, according to forum listings reviewed by security researchers and shared with CNN.

“Bad actors have won the jackpot,” said Rafi Mendelsohn, a spokesman for Cyabra, a social media analysis firm focused on identifying disinformation and inauthentic online behavior. “Previously private data such as emails, handles, and creation date can be leveraged to build smarter and more sophisticated hacking, phishing and disinformation campaigns.”

Some reports suggested the data was collected in 2021 through a bug in Twitter’s systems, a flaw the company fixed in 2022 after a separate incident in July involving 5.4 million Twitter accounts alerted the company to the vulnerability.

A view of the Twitter logo at its corporate headquarters in San Francisco, California, U.S. October 28, 2022. REUTERS/Carlos Barria Carlos Barria/Reuters With its advertising business in crisis, Twitter eases ban on political ads

Troy Hunt, a security researcher, said Thursday that his analysis of the data “found 211,524,284 unique email addresses” that had been leaked. The Washington Post earlier reported a forum listing promoting the data of 235 million accounts.

Hunt did not immediately respond to a question from CNN asking whether the records would be added to his website, haveibeenpwned.com, which allows users to search hacked records to determine if they have been affected. CNN has not independently verified the records’ authenticity.

Twitter didn’t immediately respond to a request for comment. Its communication team, along with roughly half of Twitter’s overall workforce, was gutted after billionaire Elon Musk completed his acquisition the company in late October. The significant staff reductions could now add to concerns about the company’s ability to respond to security threats.

The breadth of the leaked data could allow malicious actors or repressive governments to connect anonymous Twitter handles with the real names or email addresses of their owners, potentially unmasking dissidents, journalists, activists or other at-risk users around the world, security researchers warn.

“For those people, this is a very consequential breach,” said John Scott-Railton, a security researcher at The University of Toronto’s Citizen Lab.

The account data could also be valuable to hackers who can use the information as part of password-reset attempts and account takeovers. The risk is particularly high for individuals who use the same account credentials on Twitter as they do for other digital services such as banks or cloud storage, researchers said, because hackers could take information gleaned from the leak to pry open user accounts elsewhere.

Verified Twitter users caught up in the apparent leak, or users with particularly large followings, will be particularly valuable targets as a result of the leak, security experts warned, as those account holders may be especially influential celebrities or susceptible to extortion.

To protect themselves from phishing attempts, internet users should use unique passwords for each online service and keep track of them using a digital password manager, security researchers say. They should also enable multi-factor authentication for each of their accounts, and exercise caution when opening unsolicited email or links.

According to the cybersecurity news outlet BleepingComputer, which did claim to test the data, the latest dump appears similar to a leaked dataset advertised on hacking forums in November containing an alleged 400 million records, but slimmed down to eliminate some duplicate records. Twitter has not commented on that leak.

Reports of the leak could expand Twitter’s already significant legal and regulatory risk.

In December, Twitter’s main European privacy regulator, the Irish Data Protection Commission, said it is investigating the July 2022 leak as a possible violation of Europe’s signature privacy law, known as GDPR.

Last summer, the company’s former head of security, Peiter “Mudge” Zatko, filed a whistleblower report to the US government alleging long-ignored security vulnerabilities in Twitter’s operations. Zatko claimed that Twitter’s shortcomings on security reflected a breach of Twitter’s binding commitments to the Federal Trade Commission, a serious offense. (Twitter broadly and repeatedly pushed back at Zatko’s allegations.)

Successive incidents at Twitter have led to the company signing two consent orders with the FTC since 2011 to improve its cybersecurity posture. Violations of FTC orders can lead to fines, business restrictions and even sanctions targeting individual executives.

In November, top Twitter officials responsible for privacy and security resigned from the company, just days after Musk closed his purchase of the platform and amid the mass layoffs that in some cases cut whole departments.

Hackers post email addresses linked to 200 million Twitter accounts, security researchers say | CNN Business (2024)

FAQs

Hackers post email addresses linked to 200 million Twitter accounts, security researchers say | CNN Business? ›

Troy Hunt, a security researcher, said Thursday that his analysis of the data “found 211,524,284 unique email addresses” that had been leaked. The Washington Post earlier reported a forum listing promoting the data of 235 million accounts.

How do hackers get into Twitter accounts? ›

Twitter hacks can occur when hackers acquire your personal information via data breaches or phishing, but they can also be the result of malware or brute force attacks.

Who is Joseph James O'Connor? ›

Joseph James O'Connor, 24, pleaded guilty to cybercrime charges last month, nearly three years after he and others in his hacking group hijacked more than 130 Twitter accounts as part of a Bitcoin scam, including those of Apple, Uber, Kanye West, Bill Gates and Barack Obama.

What happened to Graham Ivan Clark? ›

He was sentenced to three years in prison followed by three years of probation as part of a plea deal under Florida's Youthful Offender Act, which limits the penalties for convicted felons under the age of 21. According to the Tampa Bay Times, he was able to serve part of his time in a military-style boot camp.

Who are the victims of Twitter hack? ›

Other supposedly compromised accounts included those of well-known individuals such as Barack Obama, Joe Biden, Bill Gates, Jeff Bezos, MrBeast, Michael Bloomberg, Warren Buffett, Floyd Mayweather Jr., Kim Kardashian, and Kanye West; and companies such as Apple, Uber, and Cash App.

How do you know if your Twitter account has been hacked? ›

Seen unintended Direct Messages sent from your account. Observed other account behaviors you didn't make or approve (like following, unfollowing, or blocking) Received a notification from us stating that your account may be compromised.

How do hackers get access to your account? ›

Keylogger programs enable hackers to spy on you, as the malware captures everything you type. Once inside, the malware can explore your computer and record keystrokes to steal passwords. When they get enough information, hackers can access your accounts, including your email, social media, and online banking.

Who is PlugwalkJoe? ›

Joseph O'Connor, 24, also known as Plugwalkjoe, was extradited from Spain in April and pleaded guilty in May to charges filed in California and New York involving a hack of Twitter, takeovers of user accounts on Snapchat and TikTok, and cyberstalking two people.

Which UK citizen extradited pleads guilty to cyber crime offenses? ›

A U.K. citizen pleaded guilty today in New York to his role in cyberstalking and multiple schemes that involve computer hacking, including the July 2020 hack of Twitter. Joseph James O'Connor, aka PlugwalkJoe, 23, was extradited from Spain on April 26.

How much money did Graham Ivan Clark make? ›

Graham Ivan Clark, 17, is accused of hacking prominent Twitter accounts. Prosecutors and the defense argued over whether the teen's considerable assets were legally obtained.

When was Twitter last hacked? ›

The most recent Twitter data breach happened in January 2023, when a database concerning over 200 million Twitter users was published on a notable hacker forum. As of October 2023, there have been no reported Twitter breaches since this incident.

How do fake Twitter accounts work? ›

These bots carry out automated actions. Their programming enables them to function like regular Twitter users. So they tweet, retweet, follow, unfollow, send Direct messages, like people's content, and reply to comments. However, they mostly retweet, and this is a sign that often gives them away.

How does a Twitter account get locked? ›

Twitter may lock or temporarily restrict certain features of your account if it suspects that it has been compromised or if it detects violations of the Twitter rules. This is indicated by a message stating that your account is locked or some features are restricted when you log in or open the app.

Does Twitter log your IP? ›

When you view Twitter content such as embedded Tweets, buttons, or timelines integrated into other websites using Twitter for Websites, Twitter may receive information, including the web page you visited, your IP address, browser type, operating system, and cookie information.

Top Articles
Latest Posts
Article information

Author: Reed Wilderman

Last Updated:

Views: 5682

Rating: 4.1 / 5 (52 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Reed Wilderman

Birthday: 1992-06-14

Address: 998 Estell Village, Lake Oscarberg, SD 48713-6877

Phone: +21813267449721

Job: Technology Engineer

Hobby: Swimming, Do it yourself, Beekeeping, Lapidary, Cosplaying, Hiking, Graffiti

Introduction: My name is Reed Wilderman, I am a faithful, bright, lucky, adventurous, lively, rich, vast person who loves writing and wants to share my knowledge and understanding with you.