AfterDawn: Tech news

Twitter confirms vulnerability resulted in over 5 million accounts exposed

Written by Matti Robinson @ 08 Aug 2022 1:22 User comments (4)

Twitter confirms vulnerability resulted in over 5 million accounts exposed

Twitter released a statement on Friday confirming that a vulnerability they had patched earlier this year was, in fact, used in a malicious attack to collect user data.
The company was forced to come clean after media reports about hacked account details surfaced on the web. According to Twitter, the company became aware of the problem in January 2022 via the company's bug bounty program. The bug had been in the code since June 2022 and was quickly fixed.

Now, the actual vulnerability and the exploit of it has to do with a form that provides the Twitter ID associated with the submitted phone number or email address. This shouldn't be publicly available, and according to a HackerOne report to Twitter, this happened even when the user had explicitly prohibited this action in the Twitter privacy settings.



This was abused to create lists consisting of Twitter IDs, phone numbers, and email addresses.

Last month Restore Privacy reported that over 5 million Twitter accounts were exposed by a hacker that was selling the database with Twitter IDs, phone numbers, and email addresses. For $30,000, the hacker by the name of "devil" claimed, you could receive information about "Celebrities, Companies, randoms, OGs, etc."



Twitter contends that there were no signs of abuse at the time of learning about the vulnerability in January 2022. While this might be possible, it seems odd that they couldn't detect any wrongdoing with an attack that likely just included a brute force-like guessing of email addresses and phone numbers, and managing to score 5.4 million account details.

Twitter has confirmed that the hacker's leaked data was retrieved using the vulnerability in question.

However, fortunately, the issue did not expose passwords and other more private information, but Twitter acknowledges that even email addresses and phone numbers attached to Twitter IDs are a grave violation of privacy. The company apologizes especially to the people that use pseudonyms, often for a very good reason, and might have been included in the more than 5 million accounts leaked.

Lastly, the company notes that if you are worried about the privacy of your phone number and email address, you might want to not add publicly known phone numbers or email addresses to the account. Furthermore, even though the hack didn't expose passwords or give access to the account itself, Twitter reminds us that having two-factor authentication enabled is good security practice.

Previous Next  

4 user comments

126.8.2022 02:37

Twitter has confirmed that a suspected data breach in July led to account data being stolen. Twitter has confirmed that the phone numbers and email addresses from 5.4 million accounts have been stolen due to the zero-day vulnerability on the platform that was originally flagged in January 2022.

229.8.2022 00:59

Nice put up. I truly like your content. It's inspiring and I absolutely like it. We are provide same services. Please go to my website. Frenco Ltd help Entrepreneurs who want to grow digitally, using modern sales channels and scale quickly worldwide. Our services includes Lead generation, A/B testing and rapid experimentation across SEO, SEM,Social media, and other marketing channels.<a href="https://frencoltd.com">FrencOltd</a>

329.8.2022 02:20

Nice put up. I truly like your content. Its inspiring and I absolutely like it. We are provide same services. Please go to my website. Frenco Ltd help Entrepreneurs who want to grow digitally, using modern sales channels and scale quickly worldwide. Our services includes Lead generation, A/B testing and rapid experimentation across SEO, SEM,Social media, and other marketing channels. https://frencoltd.com/

431.8.2022 03:04

Nice put up. I truly like your content. Its inspiring and I absolutely like it. We are provide same services. Please go to my website. Frenco Ltd help Entrepreneurs who want to grow digitally, using modern sales channels and scale quickly worldwide. Our services includes Lead generation, A/B testing and rapid experimentation across SEO, SEM,Social media, and other marketing channels. https://frencoltd.com/

Comments have been disabled for this article.

Latest news

VLC hits milestone: over 5 billion downloads VLC hits milestone: over 5 billion downloads (16 Mar 2024 4:31)
VLC Media Player, the versatile video-software powerhouse, has achieved a remarkable feat: it has been downloaded over 5 billion times.
2 user comments
Sideloading apps to Android gets easier, as Google settles its lawsuit Sideloading apps to Android gets easier, as Google settles its lawsuit (19 Dec 2023 11:09)
Google settled its lawsuit in September 2023, and one of the settlement terms was that the way applications are installed on Android from outside the Google Play Store must become simpler. In the future, installing APK files will be easier.
8 user comments
Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets (06 Jun 2023 9:19)
Roomba Combo j7+ is the very first Roomba model to combine robot vacuum with mopping features. And Roomba Combo j7+ does all that with a very clever trick, which tackles the problem with mopping and carpets. But is it any good? We found out.
Neato, the robot vacuum company, ends its operations Neato, the robot vacuum company, ends its operations (02 May 2023 3:38)
Neato Robotics has ceased its operations. American robot vacuum pioneer founded in 2005 has finally called it quits and company will cease its operations and sales. Only a skeleton crew will remain who will keep the servers running until 2028.
5 user comments
How to Send Messages to Yourself on WhatsApp How to Send Messages to Yourself on WhatsApp (20 Mar 2023 1:25)
The world's most popular messaging platform, Meta-owned WhatsApp has enabled sending messages to yourself. While at first, this might seem like an odd feature, it can be very useful in a lot of situations. ....
18 user comments

News archive