Twitter claims leaked data of 200M users not stolen from its systems

CyberTech

Level 44
Thread author
Verified
Top Poster
Well-known
Nov 10, 2017
3,250
Twitter finally addressed reports that a dataset of email addresses linked to hundreds of millions of Twitter users was leaked and put up for sale online, saying that it found no evidence the data was obtained by exploiting a vulnerability in its systems.

"In response to recent media reports of Twitter users' data being sold online, we conducted a thorough investigation and there is no evidence that data recently being sold was obtained by exploiting a vulnerability of Twitter systems," the company said.

In August, the company confirmed that a data leak impacting 5.4 million Twitter users resulted from threat actors exploiting a vulnerability fixed in January 2022.

This flaw enabled the attackers to link email addresses and phone numbers to Twitter users' accounts.

Today, Twitter said that another dataset containing email addresses linked to 200 million Twitter users that reportedly got leaked online earlier this month was not obtained by exploiting the vulnerability patched in January 2022.

Click link at source to see the rest
 

Zero Knowledge

Level 20
Verified
Top Poster
Content Creator
Dec 2, 2016
841
Right. They don't know how they got pwned, and they just don't care.

How did the hackers get the email information from twitter handles? I don't understand how they can say they weren't hacked, obviously they were.
 

upnorth

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Jul 27, 2015
5,459
The cybersecurity researchers at SafetyDetectives have discovered a dark web marketplace claiming to offer its customers access to Telegram’s internal server for $20,000.

The price, according to the seller, is non-negotiable and offers uninterrupted access to Telegram servers via the company’s employees. This means the seller has some agreement with a company insider regarding providing access to its internal servers. The merchant is offering this deal to buyers worldwide.
 

Stopspying

Level 19
Verified
Top Poster
Well-known
Jan 21, 2018
814
Right. They don't know how they got pwned, and they just don't care.

How did the hackers get the email information from twitter handles? I don't understand how they can say they weren't hacked, obviously they were.
These denials by Twitter seem to me to be similar to how Musk throws out tweets, regardless of them being based on truth, or not.
 
  • Applause
Reactions: vtqhtr413
Nov 1, 2022
28
Soo... They admit that the data was stolen and sold, but not by/to a malicious party - just to some regular "data hoarder", I presume?
And we are talking about over 200 M accounts? All of this while Twitter upkeeps a straight face?
Interesting...
 
  • Like
Reactions: Stopspying

monkeylove

Level 11
Verified
Top Poster
Well-known
Mar 9, 2014
545
According to the article, 5.4 million accounts were affected by a vulnerability fixed in January, 2022. The second, involving 200 million accounts, involve data from past leaks that were put together.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top