{"id":19802,"date":"2022-08-09T16:10:05","date_gmt":"2022-08-10T00:10:05","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/08\/09\/news-13535\/"},"modified":"2022-08-09T16:10:05","modified_gmt":"2022-08-10T00:10:05","slug":"news-13535","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/08\/09\/news-13535\/","title":{"rendered":"Twitter data breach affects 5.4M users"},"content":{"rendered":"<p>Twitter has&nbsp;<a href=\"https:\/\/privacy.twitter.com\/en\/blog\/2022\/an-issue-affecting-some-anonymous-accounts\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">confirmed<\/a>&nbsp;that&nbsp;<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hacker-selling-twitter-account-data-of-54-million-users-for-30k\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">it was breached last month<\/a>&nbsp;via a now-patched 0-day vulnerability in Twitter&rsquo;s systems, allowing an attacker to link email addresses and phone numbers to user accounts. This enabled the attacker to compile a list of 5.4 million Twitter user account profiles.<\/p>\n<blockquote>\n<p>&ldquo;We want to let you know about a vulnerability that allowed someone to enter a phone number or email address into the log-in flow in the attempt to learn if that information was tied to an existing Twitter account, and if so, which specific account. We take our responsibility to protect your privacy very seriously, and it is unfortunate that this happened.&rdquo;<\/p>\n<\/blockquote>\n<p>When a person submits a publicly known email address or phone number to Twitter, the system&nbsp;tells this person what Twitter account the email or phone number is associated with. The attacker took advantage of this and created a list containing&nbsp;5.4 million Twitter users with scraped publicly available details of the accounts, including&nbsp;whether&nbsp;the account was verified.<\/p>\n<p>This is especially worrying for users who want to remain anonymous on the platform. It&#8217;s a bit late now, but Twitter recommends anyone trying to stay anonymous should not tie a publicly known phone number or email to their Twitter account.<\/p>\n<blockquote>\n<p>If you operate a pseudonymous Twitter account, we understand the risks an incident like this can introduce and deeply regret that this happened. To keep your identity as veiled as possible, we recommend not adding a publicly known phone number or email address to your Twitter account.<\/p>\n<\/blockquote>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/twitter-confirms-zero-day-used-to-expose-data-of-54-million-accounts\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to BleepingComputer<\/a>, the attacker sold the data&nbsp;on twice,&nbsp;saying that &ldquo;the data would likely be released for free in the future.&rdquo;<\/p>\n<p>Twitter introduced the vulnerability after updating its code in June 2021. A threat hunter&nbsp;<a href=\"https:\/\/hackerone.com\/reports\/1439026\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reported<\/a>&nbsp;this vulnerability in January 2022, with Twitter eventually awarding the researcher for the find as part of its bug bounty program.<\/p>\n<p>While the company says no passwords were compromised,&nbsp;it continues to encourage users to enable&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/glossary\/multi-factor-authentication-mfa\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">two-factor authentication (2FA)<\/a>&nbsp;for their accounts, either in the form of authentication apps or hardware keys.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2022\/08\/twitter-confirmed-july-2022-data-breach-affecting-5.4m-users\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<table cellpadding='10'>\n<tr>\n<td valign='top' align='left'>\n<p>Categories: <a href='https:\/\/www.malwarebytes.com\/blog\/category\/privacy' rel='category tag'>Privacy<\/a><\/p>\n<p>Twitter has confirmed a data breach on July 2.<\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/www.malwarebytes.com\/blog\/news\/2022\/08\/twitter-confirmed-july-2022-data-breach-affecting-5.4m-users' title='Twitter data breach affects 5.4M users'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel='nofollow' href='https:\/\/www.malwarebytes.com\/blog\/news\/2022\/08\/twitter-confirmed-july-2022-data-breach-affecting-5.4m-users'>Twitter data breach affects 5.4M users<\/a> appeared first on <a rel='nofollow' href='https:\/\/www.malwarebytes.com'>Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[5897],"class_list":["post-19802","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-privacy"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19802","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19802"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19802\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19802"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19802"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19802"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}