• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Twitter: Leak of 200 Million Accounts Not Due to Historic Bug

You are here: Home / General Cyber Security News / Twitter: Leak of 200 Million Accounts Not Due to Historic Bug
January 12, 2023

A trove of about 200 million Twitter account data up for sale on the dark web lately was not obtained by any compromise of the social media firm’s IT methods, it has claimed in a new statement.

Twitter stated that the dataset was the exact same as that cited in reports of a 400 million accounts trove again in December, other than that it experienced duplicate entries removed.

Even so, it was not connected to a breach of 5.4 million users’ Twitter information confirmed in August 2022, which was traced back to a zero-working day vulnerability in the firm’s code foundation set in January previous 12 months.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


In truth, the 200m+ leak couldn’t be joined to any exploitation of Twitter’s devices, the social media huge claimed.

“Based on facts and intel analyzed to examine the issue, there is no evidence that the info remaining sold online was acquired by exploiting a vulnerability of Twitter systems,” it explained. “The information is very likely a assortment of facts currently publicly accessible on the net by unique resources.”

Twitter sought to reassure consumers by confirming that “none of the datasets analyzed contained passwords or information and facts that could lead to passwords staying compromised.”

Nevertheless, there are worries around the dataset at this time circulating on the dark web, as it links the email addresses and phone numbers on person accounts with Twitter handles.

That will put numerous customers at risk of convincing phishing attacks which could trick them into handing in excess of their credentials. That could guide to account takeover, unless of course multi-factor authentication is enabled.

Twitter did not make clear how the risk actors behind the information leak managed to link these email messages to the relevant user accounts.

“Be cautious of e-mails conveying a feeling of urgency and email messages requesting your non-public information and facts, normally double test that e-mails are coming from a legitimate Twitter resource,” it concluded by way of advice.

However, the researcher who to start with found the 200 million consumer dataset appeared unconvinced by Twitter’s most current missive, declaring a 3rd-party compromise is even now the most possible resource of the breach.

“Having talked over it with other security experts and conducting my own exploration around it, I believe that that my former assessment is however legitimate,” argued Hudson Rock CTO, Alon Gal.

“For example, the authenticity of the leak is evident in the absence of bogus positives among Twitter usernames and e-mails uncovered in the databases, [as opposed to] situations of info enrichments.”

Editorial credit: Ink Drop / Shutterstock.com


Some areas of this post are sourced from:
www.infosecurity-magazine.com

Previous Post: «Cyber Security News Royal Mail Halts International Deliveries After Cyber-Incident
Next Post: Quarter of UK SMBs Hit by Ransomware in 2022 Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.