Site navigation

Twitter Thieves Release Stolen 5.4m Non-public Records

David Paul

,

Twitter data breach
The ransomware gang stole the record, containing non-public information, earlier this year, and have now put them up on a forum for free.

More than 5.4 million non-public records of Twitter users have been shared for free on a hacker forum, after previously being stolen using an API vulnerability.

In a sign of how widely exploited the API bug has been, a security researcher has found a potentially more significant data dump of millions of Twitter records.

In July last year, a threat actor began selling the private information of over 5.4 million Twitter users on a hacking forum for $30,000, according to BleepingComputer.

The majority of the stolen consisted of public information, but also included private information, such as phone numbers and email addresses.

In December 2021, hackers acceded the data using the API vulnerability disclosed in the HackerOne bug bounty programme.

This allowed people to submit phone numbers and email addresses into the API to retrieve the associated Twitter ID. Using this, the hackers were able to ‘scrape’ public information about the account to create a user record containing both private and public information.

BleepingComputer said it had shared a sample of the user records with earlier this year Twitter, and the social media company confirmed they had suffered a data breach using an API bug fixed in January 2022.

Owner of the Breached hacking forum, Pompompurin, said that they were responsible for exploiting the bug and creating the massive dump of Twitter user records after another threat actor known as ‘Devil’ shared the vulnerability with them.

In addition to the 5.4 million records for sale, there were also an additional 1.4 million Twitter profiles for suspended users collected using a different API, bringing the total to almost 7 million Twitter profiles containing private information.

The second data dump was not sold and was only shared privately among a few people, according to Pompompurin. They added that this is the same data that was for sale in August and includes the 5.4m Twitter user records.

These records contain either a private email address or phone number, and public scraped data, including the account’s Twitter ID, name, screen name, verified status, location, URL, description, follower count, account creation date, friends count, favorites count, statuses count, and profile image URLs.


Recommended


Jamie Akhtar, CEO and co-founder of CyberSmart commented: “This is a potentially colossal breach that could affect millions of people. As the information is out there, you can be sure that cybercriminals will try to leverage it. So, if you’re a twitter user, there are a few things worth doing to protect yourself.

“First of all, change your password. Although there’s been no mention of password data being leaked, it’s sensible to do it anyway as a failsafe. Second, be on your guard. If you receive emails (claiming to be from Twitter) suggesting your account has been suspended, you’re about to lose your verified status or there are log in issues, ignore them.

“Also, check any emails you receive from ‘Twitter’ send you to a Twitter URL. Anything else is likely to be a phishing attempt. As we said, this is a serious breach and there’s likely to be a sharp uptick in Twitter-related scams. However, provided users take steps to protect themselves it doesn’t have to become a disaster.”


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

David Paul

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data