• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Twitter: Leak of 200 Million Accounts Not Due to Historic Bug

You are here: Home / General Cyber Security News / Twitter: Leak of 200 Million Accounts Not Due to Historic Bug
January 12, 2023

A trove of about 200 million Twitter account data up for sale on the dark web lately was not obtained by any compromise of the social media firm’s IT methods, it has claimed in a new statement.

Twitter stated that the dataset was the exact same as that cited in reports of a 400 million accounts trove again in December, other than that it experienced duplicate entries removed.

Even so, it was not connected to a breach of 5.4 million users’ Twitter information confirmed in August 2022, which was traced back to a zero-working day vulnerability in the firm’s code foundation set in January previous 12 months.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


In truth, the 200m+ leak couldn’t be joined to any exploitation of Twitter’s devices, the social media huge claimed.

“Based on facts and intel analyzed to examine the issue, there is no evidence that the info remaining sold online was acquired by exploiting a vulnerability of Twitter systems,” it explained. “The information is very likely a assortment of facts currently publicly accessible on the net by unique resources.”

Twitter sought to reassure consumers by confirming that “none of the datasets analyzed contained passwords or information and facts that could lead to passwords staying compromised.”

Nevertheless, there are worries around the dataset at this time circulating on the dark web, as it links the email addresses and phone numbers on person accounts with Twitter handles.

That will put numerous customers at risk of convincing phishing attacks which could trick them into handing in excess of their credentials. That could guide to account takeover, unless of course multi-factor authentication is enabled.

Twitter did not make clear how the risk actors behind the information leak managed to link these email messages to the relevant user accounts.

“Be cautious of e-mails conveying a feeling of urgency and email messages requesting your non-public information and facts, normally double test that e-mails are coming from a legitimate Twitter resource,” it concluded by way of advice.

However, the researcher who to start with found the 200 million consumer dataset appeared unconvinced by Twitter’s most current missive, declaring a 3rd-party compromise is even now the most possible resource of the breach.

“Having talked over it with other security experts and conducting my own exploration around it, I believe that that my former assessment is however legitimate,” argued Hudson Rock CTO, Alon Gal.

“For example, the authenticity of the leak is evident in the absence of bogus positives among Twitter usernames and e-mails uncovered in the databases, [as opposed to] situations of info enrichments.”

Editorial credit: Ink Drop / Shutterstock.com


Some areas of this post are sourced from:
www.infosecurity-magazine.com

Previous Post: «Cyber Security News Royal Mail Halts International Deliveries After Cyber-Incident
Next Post: Quarter of UK SMBs Hit by Ransomware in 2022 Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New HTTPBot Botnet Launches 200+ Precision DDoS Attacks on Gaming and Tech Sectors
  • Top 10 Best Practices for Effective Data Protection
  • Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks
  • Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks
  • [Webinar] From Code to Cloud to SOC: Learn a Smarter Way to Defend Modern Applications
  • Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit
  • Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails
  • Pen Testing for Compliance Only? It’s Time to Change Your Approach
  • 5 BCDR Essentials for Effective Ransomware Defense
  • Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers

Copyright © TheCyberSecurity.News, All Rights Reserved.