Twitterโcurrently a company enduring more than one major headacheโhas a pretty bad data breach on its hands. It could impact hundreds of millions of users and lead to major security issues for the platform but, despite its severity, itโs been easy to miss amidst the flood of other scandals and controversies plaguing the social media giant. Still, if you use the bird app, this is one mess youโre definitely gonna want to pay attention to, as it might affect you directly, unlike Elon Muskโs c-suite uproar.
The short version is this: data stolen from Twitter more than a year ago found its way onto a major dark web marketplace this week. The asking price? The crypto equivalent of $2. The hacker who posted the data haul, a user who goes by the moniker โStayMad,โ posted the data to the market โBreached,โ where anyone can now purchase and peruse it. The cache is estimated to cover at least 235 million peopleโs information.
While a lot of details are still missing from this unfortunate saga, weโve pulled together a short rundown on what you might need to know about Twitterโs security debacle, the latest in a long string.
What information was compromised?
According to multiple reports, the breach material includes the email addresses and/or phone numbers of some 235 million people. This information has been paired with details publicly scraped from usersโ profiles, thus allowing the cybercriminals to create more complete data dossiers on potential victims. Bleeping Computer reports that the information for each user includes not only email addresses and phone numbers but also names, screen names/user handles, follower count, and account creation date. In short: anybody who buys the haul from โBreachedโ will have the contact and partial login information for any impacted Twitter user. Not only is this a potential security issue for those accounts, itโs a major privacy violation for anybody who doesnโt want random dark web goons to have access to their contact info.
G/O Media may get a commission
How and when did this happen?
The data that appeared on โBreachedโ this week was actually stolen during 2021. Per the Washington Post, cybercriminals exploited an API vulnerability in Twitterโs platform to call up user information connected to hundreds of millions of user accounts. This bug created a bizarre โlookupโ function, allowing any person to plug in a phone number or email to Twitterโs systems, which would then verify whether the credential was connected to an active account. The bug would also reveal which specific account was tied to the credential in question.
The vulnerability was originally discovered by Twitterโs bug bounty program in January of 2022 and was first publicly acknowledged last August. In a blog post, the company said that the bug had been the result of an update to its code that took place in June of 2021. At that point, the company told users that it had โno evidence to suggest someone had taken advantage of the vulnerabilityโ though, as it turns out, they were totally wrong.
Itโs unclear exactly when cybercriminals discovered this bug and began exploiting it but what we do know is that, by the time the platform caught on, the hackers had already stolen data from a shitload of people. That said, the total amount of information inside the โBreachedโ haul that is authentic is unknown. Analysts and journalists have tested portions of the data and found it to involve real accounts.
Who is behind the hack?
We donโt know. The identities of the cybercriminals behind the data breach are unknown, and itโs unclear whether they have ties to a well-known hacker group or threat actor. The user who posted the 200 million profile haul on Breached goes by the moniker โStayMad,โ but little is known about them outside of that. While we might not know who is responsible for the data breach, security experts have speculated that cybercriminals could use the stolen data to conduct a whole slew of unsavory activities. Experts have estimated that the information could be used for account takeover attempts, as well as phishing and harassment of affected users.
What has Twitter done about it?
As far as we can tell, Twitter has done almost nothing about the most recent iteration of this data breach. After acknowledging the API bug last summer, the company hasnโt offered many updates, nor has it commented on the recent listing of user data for sale. Gizmodo reached out to the company on Thursday for comment about the โBreachedโ incident but did not hear back. Twitter no longer has a public relations department after Elonโs layoffs. We will update our story if the platform decides to ever address the security debacle.
What You Can Do
Unfortunately, thereโs not much you can do. Unless you buy the data yourself and sift through it, itโs not clear how you would verify whether you were impacted or not. However, if youโre concerned that your data may have been exposed, one recommendation would be to burn the account credentials that may have been affected by the breach. An email address can be easy to change but an exposed phone number is a little more complicated. Phone numbers are less discardable than emailsโthough you can always contact your cellular provider and request a phone number change if youโre worried about your privacy. At the same time, you should change the email address and/or phone number associated with your Twitter account and employ multi-factor authentication that puts the accountโs security firmly in your hands (thatโs how itโs supposed to work, anyway).
Read More: news.google.com