Dataconomy
  • News
  • AI
  • Big Data
  • Machine Learning
  • Trends
    • Blockchain
    • Cybersecurity
    • FinTech
    • Gaming
    • Internet of Things
    • Startups
    • Whitepapers
  • Industry
    • Energy & Environment
    • Finance
    • Healthcare
    • Industrial Goods & Services
    • Marketing & Sales
    • Retail & Consumer
    • Technology & IT
    • Transportation & Logistics
  • Events
  • About
    • About Us
    • Contact
    • Imprint
    • Legal & Privacy
    • Newsletter
    • Partner With Us
    • Writers wanted
Subscribe
No Result
View All Result
Dataconomy
  • News
  • AI
  • Big Data
  • Machine Learning
  • Trends
    • Blockchain
    • Cybersecurity
    • FinTech
    • Gaming
    • Internet of Things
    • Startups
    • Whitepapers
  • Industry
    • Energy & Environment
    • Finance
    • Healthcare
    • Industrial Goods & Services
    • Marketing & Sales
    • Retail & Consumer
    • Technology & IT
    • Transportation & Logistics
  • Events
  • About
    • About Us
    • Contact
    • Imprint
    • Legal & Privacy
    • Newsletter
    • Partner With Us
    • Writers wanted
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

400 million Twitter accounts’ data is on Christmas sale

by Eray Eliaçık
December 26, 2022
in Cybersecurity, News
Home Cybersecurity
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail

400 million Twitter accounts are affected by a massive Twitter data breach according to a hacker. Twitter CEO Elon Musk has been urged in a post on a criminal data breach forum by a member who claims to have gotten the emails and phone numbers of 400 million Twitter users.

With users flocking to the rival Mastodon, controversial new view count feature, and now the breach; Elon Musk seems to have no end of troubles to deal with. The seller, a member of data breach forums named Ryushi, claims the data was scraped via a Twitter vulnerability. Vitalik Buterin, Sundar Pichai, Mark Cuban, and others are among those whose data was allegedly compromised.

Table of Contents

  • Twitter data breach: 400 million users affected according to a hacker
  • Twitter data breach: How did alleged hack happen?
  • Outcomes of similar major data breaches: Equifax & T-Mobile

Twitter data breach: 400 million users affected according to a hacker

Over 400 million Twitter accounts have had their data exposed and are now for sale on the deep web. The hacker claims the information is confidential and contains the email addresses and phone numbers of famous people, government officials, businesses, and normal users. An Israeli cyber intelligence agency called Hudson Rock reportedly discovered the posting first.

BREAKING: Hudson Rock discovered a credible threat actor is selling 400,000,000 Twitter users data.

The private database contains devastating amounts of information including emails and phone numbers of high profile users such as AOC, Kevin O'Leary, Vitalik Buterin & more (1/2). pic.twitter.com/wQU5LLQeE1

— Hudson Rock (@RockHudsonRock) December 24, 2022


Join the Partisia Blockchain Hackathon, design the future, gain new skills, and win!


A sample of the data was shared on one of the hacker forums by the hacker to demonstrate the authenticity of the data. The followings are included in the Twitter data breach sample data:

  • Email addresses
  • Names
  • Usernames
  • Numbers of followers
  • Profiles’ dates of creation
  • Phone numbers

The shocking part is that the hacker released sample data from high-profile user accounts. The Twitter data breach sample includes information from the following sources:

  • Alexandria Ocasio-Cortez
  • SpaceX
  • CBS Media
  • Donald Trump Jr.
  • Doja Cat
  • Charlie Puth
  • Sundar Pichai
  • Salman Khan
  • NASA’s JWST account
  • NBA
  • Ministry of Information and Broadcasting, India
  • Shawn Mendes
  • Social Media of WHO

Many more data from high-profile users can be found in the sample set. If the data leak is real, it will be incredibly destructive, but most of the traces will point to the social media team. Hudson Rock co-founder and CTO Alon Gal speculate that the information was accessed through an API vulnerability that allowed the threat actor to query any email or phone number and receive a Twitter profile.

“Twitter or Elon Musk if you are reading this you are already risking a GDPR fine over 5.4m breach imagine the fine of 400m users breach source. Your best option to avoid paying $276 million USD in GDPR breach fines like facebook did (due to 533m users being scraped) is to buy this data exclusively.”

The hacker explains his motives in his post

400 million Twitter accounts' data is on Christmas sale
Twitter is known for its real-time news and information-sharing capabilities and has been used by journalists, politicians, and celebrities to share updates and engage with their followers. It has also been used to organize social and political movements, and to facilitate the spread of information during crises.

The Twitter data breach hacker indicates that he is willing to negotiate the ‘Deal’ through a middleman:

“After that I will delete this thread and will not sell this data again. And data will not be sold to anyone else which will prevent a lot of celebrities and politicians from Phishing, Crypto scams, Sim swapping, Doxxing and other things that will make your users Lose trust in you as a company and thus stunt the current growth and hype that you are having also just imagine famous content creators and influencers getting hacked on twitter that will for sure Make them ghost the platform and ruin your dream of twitter video sharing platform for content creators, also since you Made the mistake of changing twitter policy that got an immense backlash.”

The hacker

According to Alon Gal, Twitter has inserted a “readers context” in which they credit the database of 400,000,000 Twitter users to the data leak in August that affected 5,400,000 users.

“This is easily disproved by comparing the samples in the new leak to the older 5.4m version which had already been leaked publicly. 250 out of 1000 are found. (the count would have been lower had it been a sample of non-verified accounts) I can’t share some sensitive information I have, but as time goes on I am more confident this is a 400,000,000 users leak, and as always, it will unfortunately leak to the hands of every hacker for free.”

Alon Gal

After slamming Twitter’s business and policies with a sledgehammer, Elon Musk may find himself on the receiving end of a massive data breach. The DPC is currently looking into the earlier security breach.

400 million Twitter accounts' data is on Christmas sale
Twitter was founded in 2006 by Jack Dorsey, Biz Stone, and Evan Williams.

The Twitter data breach claim came a day after the Irish Data Protection Commission (DPC) stated it would look into a prior Twitter data leak that affected over 5.4 million users.


Mastodon vs Twitter: Everything you need to know


Have you ever wondered what could happen if an open-source Twitter algorithm existed? We did.

Twitter data breach: How did alleged hack happen?

The Twitter data breach seller, identified as Ryushi, a frequent contributor to hacker forums, asserts that the information was obtained via exploiting a security hole. While the Twitter data breach allegedly happened, hacker Sunny Nehra hinted that more information was stolen through the same vulnerability.

According to reports, the hacker is attempting to sell the data, which includes contact information for prominent Twitter users like Alphabet and Google CEO Sundar Pichai, Bollywood actor Salman Khan, the Indian Ministry of Information and Broadcasting, Elon Musk’s SpaceX, CBS Media, Donald Trump Jr., and American politician Alexandria Ocasio-Cortez.

2/ Twitter had accepted that the said API flaw was abused in the wild but it’s high time now that they also confirm how many exact users and who all were infected (alert all those users). We can’t wait for some or other new dumps related to the same flaw getting leaked with time.

— Sunny Nehra (@sunnynehrabro) December 26, 2022

According to reports, the Twitter data breach hacker is negotiating a purchase of the data with Twitter CEO Musk in an effort to sidestep potential GDPR-related legal action.

The hacker claims that they will destroy the data and not sell it to anyone else if Musk pays the ransom “to avoid a lot of celebrities and politicians from Phishing, Crypto frauds, Sim swapping, Doxxing, and other things.”

Targeted phishing attempts via text and email, sim switch attacks to get access to accounts, and doxing are all possible outcomes of a data breach using such information.

400 million Twitter accounts' data is on Christmas sale
As of December 2022, Twitter had over 368 million monthly active users.

The supposed hacker’s Breached post promoting the database for sale is still active as of this writing.

Users are urged to take measures such as using a private, self-hosted crypto wallet, changing their passwords frequently, and storing them safely, and using two-factor authentication settings (through an app rather than their phone number) on all of their accounts.


Data breaches and hacks are today’s biggest problems. Check out the latest data breaches and hacks before we continue: CHI Health data breach, Facebook data breach, Uber security data breach, American Airlines data breach, Medibank cyber attack, and Binance hack.


Outcomes of similar major data breaches: Equifax & T-Mobile

The credit reporting firm Equifax acknowledged on September 7, 2017, that one of its computer networks had had a data leak that had exposed the personal information of 143 million clients, which eventually rose to 147 million. These records included information about the customers’ names, residences, dates of birth, Social Security numbers, and credit card numbers, all of which may be exploited for fraud and identity theft.

Equifax agreed to establish a fund to provide customers with free credit monitoring, identity theft protection, and cash compensation of up to $20,000 per to people harmed by the event, per the deal’s conditions. Additionally, the company must pay court fees and government fines.

Take a closer look at how data breaches effects companies: Equifax Data breach settlement

Medibank Cyber Attack: Medibank Confirmed The Ransomware Hack

The cybersecurity vulnerability was first disclosed by T-Mobile and was made public on August 16, 2021. According to reports, almost 77 million consumers’ personally identifiable information was stolen due to the T-Mobile data breach. This contained database data such as addresses, dates of birth, social security numbers, driver’s license numbers, unique IMEIs and identification codes for client phones, and so on.

If granted, the $350 million T-Mobile deal will represent US history’s second-largest payment for a data breach.

Take a closer look at how data breaches effects companies: T-Mobile Data Breach Settlement

    • Other settlements that made the news this year: Epic Games settlement, ATT settlement, Tiktok data privacy settlement, Snapchat privacy settlement, and Google location tracking lawsuit settlement

 

 

Tags: Data BreachhackerTwitter

Related Posts

How did ChatGPT passed an MBA exam

How did ChatGPT passed an MBA exam?

January 27, 2023
Google code red: ChatGPT and You.com like AI-powered tools threatening the search engine. Moreover, latest Apple Search rumors increased the danger.

Google code red: ChatGPT, You.com and rumors of Apple Search challenge the dominance of search giant

January 26, 2023
Top 5 cybersecurity analytics tools

Navigating the evolving landscape of cyber threats by utilizing advanced data analytics

January 20, 2023
T-Mobile data breach 2023 explained: Learn how did the leak happen and explore T-Mobile data breach history. It is not the first time of the company

T-Mobile data breach 2023: The telecom giant got hacked eight times in the last six years

January 20, 2023
Microsoft layoffs 2023: Amazon job cuts that affect 11,000 employees explained. Big tech layoffs continue... Learn why and what will happen next.

Microsoft layoffs will affect more than 11,000 employees

January 18, 2023
Medibank Data Breach Class Action: Compensation can reach up to $20,000 per person

Medibank Data Breach Class Action: Compensation can reach up to $20,000 per person

January 16, 2023

LATEST ARTICLES

How did ChatGPT passed an MBA exam?

AI prompt engineering is the key to limitless worlds

Transform your data into a competitive advantage with AaaS

Google code red: ChatGPT, You.com and rumors of Apple Search challenge the dominance of search giant

Tome AI offers a new way to create presentations easily

Transforming data into insightful information with BI reporting

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy
  • Partnership
  • Writers wanted

Follow Us

  • News
  • AI
  • Big Data
  • Machine Learning
  • Trends
    • Blockchain
    • Cybersecurity
    • FinTech
    • Gaming
    • Internet of Things
    • Startups
    • Whitepapers
  • Industry
    • Energy & Environment
    • Finance
    • Healthcare
    • Industrial Goods & Services
    • Marketing & Sales
    • Retail & Consumer
    • Technology & IT
    • Transportation & Logistics
  • Events
  • About
    • About Us
    • Contact
    • Imprint
    • Legal & Privacy
    • Newsletter
    • Partner With Us
    • Writers wanted
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.