
The email addresses and phone numbers of more than 400 million Twitter users has been put up for sale on the hacker Breached Forums.
Cyber Security Hub reported it was posted by a hacker using the screen name “Ryushi” claiming to have collected the data by utilizing a “data scraping technique”
The hacker demanded $200,000 and blamed Twitter for allowing its data to be hacked,
Your best option to avoid paying $276 million USD in GDPR breach fines like Facebook did…is to buy this data exclusively.”
It included sample data for Doja Cat, AOC, the WHO, Shawn Mendes, and Piers Morgan.
Privacy Affairs said that they had found evidence that the account details of over 200 million Twitter users had been leaked on the hacker forum for FREE.
Veronika Biliavska, content manager at Privacy Affairs, said to Forbes via an email,
This new leak appears to be the same as the one reported in December 2022 that affected over 400 million accounts.
The 200 million number, in this case, resulted from the removal of duplicates.”
The data is now apparently available for anyone to download for free, instead of being listed for sale for $200,000, as it was in December.
This shouldn’t be dismissed, especially for those posting controversial info under anonymous accounts.
Miklos Zoltan, CEO of Privacy Affairs said,
This leak essentially doxxes the personal email addresses of high profile users, which can be used for spam, harassment and even attempts to hack those accounts. High profile users may end up getting inundated with spam and phishing attempts on a mass scale.”
Cybersecurity researcher Steve Hahn, executive vice president at BullWall said,
This threat actor began the monetization of this event with extortion of important people and that is how it’s likely to end.
Back in December, Elon Musk himself was being extorted as the result of this breach:
‘Pay our fee or we leak your Twitter data.’
Now imagine the doxing that can occur with this data in the wrong hands.
A married public official with an anonymous account following, liking, and commenting on a sex worker’s Twitter pics, or a disgruntled employee with an NDA posting incriminating leaks on a former employer.”
Even the average user who may have posted controversial things, if info was released could get them canceled or fired. Hahn said,
With this data so widely available; any mischievous or nefarious person can collect the names tied to ‘anonymous’ Twitter handles and begin ‘screenshotting’ their activity and attempt to extort or embarrass those individuals.
This is a political opposition researcher’s dream. For the rest of us, it’s a nightmare. It’s also a good reminder to use unique passwords for every site.”
The takeaway from this for me, start changing passwords today, and make them unique.
Leaked Emails of 200M @Twitter Users Now Available for Free. (Data Breach Today) #DataBreach #Data #Breach #Privacy https://t.co/43WAoneolJ pic.twitter.com/eV7WYdPd5a
— James Gingerich @Expeflow #CES2023 #RPA #InsurTech (@jamesvgingerich) January 5, 2023
(via Forbes)