28 November 2022

5.4 million Twitter users' stolen data offered for free on hacker forum


5.4 million Twitter users' stolen data offered for free on hacker forum

More than 5.4 million Twitter user records containing data stolen via an API vulnerability fixed in January have been leaked for free on a cybercriminal forum. Furthermore, it appears that there may be another, even larger data damp, containing about 17 million Twitter user’s records obtained via the same vulnerability, according to tech news site BleepingComputer.

In July, reports emerged that the private information of over 5.4 million Twitter users was put up for sale on a hacking forum for a price of $30,000. The database contained both public information like Twitter IDs, names, login names, locations, and verified status, and the private data, such as phone numbers and email addresses.

In addition to the 5.4 million records for sale, there were also an additional 1.4 million Twitter profiles for suspended users collected using a different API, bringing the total to almost 7 million Twitter profiles containing private information, BleepingComputer reports.

Starting September, the same 5.4 million Twitter records were observed being shared for free on a hacking forum.

As for the new, previously unknown data dump, disclosed by a security researcher, it allegedly contains information of tens of millions Twitter users in the US and EU, including personal phone numbers, as well as public information.

Twitter has yet to comment on this alleged breach.

Back to the list

Latest Posts

Cyber Security Week in Review: May 10, 2024

Cyber Security Week in Review: May 10, 2024

In brief: Google fixes yet another Chrome 0Day, Dell suffers a data breach, the LockBit leader identified, and more.
10 May 2024
Massive BogusBazaar fraud ring steals credit cards from thousands of victims

Massive BogusBazaar fraud ring steals credit cards from thousands of victims

As of April 2024, approximately 22,500 domains were active.
9 May 2024
Poland’s government institutions targeted in Russian cyberespionage campaign

Poland’s government institutions targeted in Russian cyberespionage campaign

The incident marks the latest in a string of Russian cyberattacks aimed at NATO-allied nations supporting Ukraine.
9 May 2024