200 million Twitter users' email addresses allegedly leaked online (2024)

200 million Twitter users' email addresses allegedly leaked online (1)

A data leak described as containing email addresses for over 200 million Twitter users has been published on a popular hacker forum for about $2. BleepingComputer has confirmed the validity of many of the email addresses listed in the leak.

Since July 22nd, 2022, threat actors and data breach collectors have been selling and circulating large data sets of scraped Twitter user profiles containing both private (phone numbers and email addresses) and public data on various online hacker forums and cybercrime marketplaces.

These data sets were created in 2021 by exploiting aTwitter API vulnerabilitythat allowed users to input email addresses and phone numbers to confirm whether they were associated with a Twitter ID.

The threat actors then used another API to scrape the public Twitter data for the ID and combined this public data with private email addresses/phone numbers to create profiles of Twitter users.

Though Twitter fixed this flawin January 2022, multiple threat actors have recently begun to leak the data sets they collected over a year ago for free.

Thefirst data set of 5.4 million userswas put up for sale in July for $30,000 and ultimatelyreleased for freeon November 27th, 2022. Another data set allegedly containing the data for 17 million users was also circulating privately in November.

More recently, a threat actor began selling a data set that they claimed contained 400million Twitter profiles collected using this vulnerability.

200 million lines of Twitter profiles released for free

Today, a threat actor released a data set consisting of 200 million Twitter profiles on the Breached hacking forum for eight credits of the forum's currency, worth approximately $2.

This data set is allegedly the same as the 400 million set circulating in November but cleaned up to not contain duplicates, reducing the total to around 221,608,279 lines.However, BleepingComputer's tests have also confirmed duplicates in this latestleaked data.

200 million Twitter users' email addresses allegedly leaked online (2)

The data was released as a RAR archive consisting of six text files for a combined size of 59 GB of data.

200 million Twitter users' email addresses allegedly leaked online (3)

Each line in the files represents a Twitter user and their data, which includes email addresses, names, screen names, follow counts, and account creation dates, as shown below.

200 million Twitter users' email addresses allegedly leaked online (4)

Unlike previously leaked data collected using this Twitter API flaw, today's leak does not indicate whether an account is verified.

While BleepingComputer has been able to confirm that the email addresses are correct for many of the listed Twitter profiles, the full data set has obviously not been confirmed.

Furthermore, the data set is far from complete, as there were many users who were not found in the leak.

Whether or not your information is in this data set highly depends on whether your email address was exposed in previous data breaches.

In 2021, the threat actors created massive lists of email addresses and phone numbers that were exposed in previous data breaches.

The scrapers then fed these lists into the API bug to see if your number or email address was associated with a corresponding Twitter ID with the email or phone number.

If your email address is only used at Twitter or was not in many data breaches, it would not have been fed into the API bug and added to this data set.

BleepingComputer has contacted Twitter regarding this leaked data but has not received a response to this or our previous emails.

Is your email in the leak?

Data breach notification serviceHave I Been Pwned(HIBP) has added the Twitter data leak to its system and has begun notifying subscribers if their email was found in the data set.

Troy Hunt, the creator of HIBP, told BleepingComputer that there is a total of 211,524,284 unique email addresses in the leak, down from the original number of 221,608,279 lines.

To check if your email is part of the Twitter leak, you can visit Have I Been Pwned and search with your email. If your email is part of the leak, HIBP will notify you with the list of detected data breaches, including the Twitter one, shown below.

200 million Twitter users' email addresses allegedly leaked online (5)

What should you do if your listed?

Even though this data leak only contains email addresses, it could be used by threat actors to conduct phishing attacks against accounts, especially verified ones.

Verified accounts with large followers are highly valued as they are often used to steal cryptocurrency through online scams.

This leak is also a significant privacy concern, especially for Twitter users who tweet anonymously. With this leak, it may be possible to identify anonymous Twitter users and expose their real identities.

All Twitter users should be on the lookout for targeted phishing scams that attempt to steal your passwords or other sensitive information.

Unfortunately, if you are concerned about your identity being revealed by a leaked email address, there is not much you can do.

Update 1/5/23: Twitter users can now search on Have I Been Pwned to see if they are in the leak.

200 million Twitter users' email addresses allegedly leaked online (6)

Related Articles:

Cox fixed an API auth bypass exposing millions of modems to attacks

Dallas County: Data of 200,000 exposed in 2023 ransomware attack

GitLab: Critical bug lets attackers run pipelines as other users

CISA urges devs to weed out OS command injection vulnerabilities

CISA urges software devs to weed out SQL injection vulnerabilities

200 million Twitter users' email addresses allegedly leaked online (2024)

FAQs

200 million Twitter users' email addresses allegedly leaked online? ›

Hackers reportedly leak email addresses of more than 200 million Twitter users. Hackers stole the email addresses of more than 200 million Twitter users and posted them on an online hacking forum

hacking forum
Hack Forums (often shortened to 'HF') is an Internet forum dedicated to discussions related to hacker culture and computer security.
https://en.wikipedia.org › wiki › Hack_Forums
, a security researcher said on Wednesday.

How did Twitter account get hacked? ›

Twitter hacks can occur when hackers acquire your personal information via data breaches or phishing, but they can also be the result of malware or brute force attacks.

What happened with the Twitter data breach? ›

Hackers exploited an API vulnerability to gain unauthorized access to Twitter's user data, matching email addresses with profiles. This security flaw persisted from June 2021 to January 2022, ultimately leading to the exposure of email addresses, names, and usernames for millions of users.

How many Twitter accounts are hacked? ›

Data alleged to contain the email addresses of more than 200 million Twitter users is being given away for free on a hacker forum, reports say. The stolen information includes email addresses used to set up accounts, which will worry anonymous users who registered with a sensitive address.

When was the last time Twitter got hacked? ›

2022: “Devil” Hacker Steals 5.4M Twitter Users' Data

In July 2022, self-titled “devil” hacker posted on the hacking forum, BreachForums, that they had stolen the personal information of 5.4 million Twitter users, as reported by Firewall Times.

How to spot a scammer on Twitter? ›

11 Easy Ways To Spot a Fake Twitter Account Instantly
  1. They Are An Egghead.
  2. They Use Stock Profile Images.
  3. No Bio.
  4. Excessive Duplicate Tweets.
  5. Confusing Screen Name / URL Combination.
  6. Incoherent Tweets.
  7. Has Not Tweeted in Years.
  8. Follows 2,001 People.

Should I be worried if my Twitter account was hacked? ›

A compromised Twitter account can impact your privacy.

If someone has access to your Twitter account, they have access to your information associated with that account, such as your phone number. Privacy is only becoming more important, and there can be greater consequences when personal information is accessed.

What is the world's largest data leak? ›

The supermassive leak contains data from numerous previous breaches, comprising an astounding 12 terabytes of information, spanning over a mind-boggling 26 billion records. The leak, which contains LinkedIn, Twitter, Weibo, Tencent, and other platforms' user data, is almost certainly the largest ever discovered.

Can I sue Twitter for data breach? ›

When data protection standards have fallen short, and in this case a hack has enabled unauthorised access to your personal data, you can make a claim for compensation. Bringing a data breach claim not only gets you access to compensation, but also holds a company or organisation to account for their actions.

What is 26 billion records exposed? ›

The Scale of the Breach and The Supermassive Leak

The supermassive leak consists of a mind-boggling 12 terabytes of information, spanning over 26 billion records. The data breach has had a significant impact on data privacy and information security, raising cybersecurity concerns worldwide.

What is the most common way accounts are hacked? ›

Phishing

One of the most common attacks, phishing, occurs when a hacker pretends to be a legitimate entity, such as your bank and requests sensitive information, such as your password.

Can you see how many devices are logged into your Twitter? ›

Click on the Security And Account Access option. Step 4: A list of options will again pop up there. Among them, click on the Apps & Session option. Step 5: Click on the Session option to check all the devices that are used for login in Twitter.

Is Twitter a security risk? ›

One of the most significant risks on Twitter is phishing attacks. These attacks often come in the form of emails or direct messages (DMs) that appear to be from a legitimate source, such as Twitter itself. These messages often include a link that, once clicked, will take the user to a fake Twitter login page.

What is Twitter Zero-Day? ›

The reason it's referred to as a "zero-day" vulnerability is that the software vendor essentially has "zero time" to patch it before it is exploited once a threat actor discovers the vulnerability. Software bugs, weak passwords, or a lack of authorization and encryption can all lead to zero-day vulnerabilities.

Has the number of Twitter users fallen? ›

Use of Twitter in the US has slumped by more than a fifth since Elon Musk bought the site and rebranded it to X, according to data from app-monitoring company Sensor Tower. As of February 2024, the social network's daily app users in America had fallen by 23% since November 2022, just after Musk completed his takeover.

How many Twitter accounts were fake? ›

Our analysis found that 19.42%, nearly four times Twitter's Q4 2021 estimate, fit a conservative definition of fake or spam accounts (i.e. our analysis likely undercounts).

How did your account get hacked? ›

People who say their accounts have been "hacked" are likely guilty of re-using passwords, installing a key logger, or giving their credentials to an attacker after social engineering tricks. They may also have been compromised as a result of easily guessed security questions.

Can you get hacked off of Twitter? ›

X may suspend accounts, temporarily or permanently, from their social networking service. Suspensions of high-profile accounts often attract media attention, and X's use of suspensions has been controversial.

How can I get my Twitter account back? ›

If your account was hacked and you can no longer log in, fill out the form at https://help.twitter.com/en/forms/account-access/regain-access/hacked-or-compromised.

How does Twitter detect fake accounts? ›

[6], which reveals that “user activity”, such as the amount of tweets, profile, and friend counts, can be used to identify false accounts by utilizing graph approaches as well as detection analysis with a machine learning algorithm on well-defined datasets associated with the features highlighted.

Top Articles
Citibank Branch Locations In Orlando Florida
Condado Happy Hour Times, Menu with Prices Guide 2024
Spasa Parish
Rentals for rent in Maastricht
159R Bus Schedule Pdf
Sallisaw Bin Store
Black Adam Showtimes Near Maya Cinemas Delano
Espn Transfer Portal Basketball
Pollen Levels Richmond
11 Best Sites Like The Chive For Funny Pictures and Memes
Things to do in Wichita Falls on weekends 12-15 September
Craigslist Pets Huntsville Alabama
Paulette Goddard | American Actress, Modern Times, Charlie Chaplin
Red Dead Redemption 2 Legendary Fish Locations Guide (“A Fisher of Fish”)
What's the Difference Between Halal and Haram Meat & Food?
R/Skinwalker
Rugged Gentleman Barber Shop Martinsburg Wv
Jennifer Lenzini Leaving Ktiv
Justified - Streams, Episodenguide und News zur Serie
Epay. Medstarhealth.org
Olde Kegg Bar & Grill Portage Menu
Cubilabras
Half Inning In Which The Home Team Bats Crossword
Amazing Lash Bay Colony
Juego Friv Poki
Dirt Devil Ud70181 Parts Diagram
Truist Bank Open Saturday
Water Leaks in Your Car When It Rains? Common Causes & Fixes
What’s Closing at Disney World? A Complete Guide
New from Simply So Good - Cherry Apricot Slab Pie
Drys Pharmacy
Ohio State Football Wiki
Find Words Containing Specific Letters | WordFinder®
FirstLight Power to Acquire Leading Canadian Renewable Operator and Developer Hydromega Services Inc. - FirstLight
Webmail.unt.edu
2024-25 ITH Season Preview: USC Trojans
Navy Qrs Supervisor Answers
Trade Chart Dave Richard
Lincoln Financial Field Section 110
Free Stuff Craigslist Roanoke Va
Wi Dept Of Regulation & Licensing
Pick N Pull Near Me [Locator Map + Guide + FAQ]
Crystal Westbrooks Nipple
Ice Hockey Dboard
Über 60 Prozent Rabatt auf E-Bikes: Aldi reduziert sämtliche Pedelecs stark im Preis - nur noch für kurze Zeit
Wie blocke ich einen Bot aus Boardman/USA - sellerforum.de
Infinity Pool Showtimes Near Maya Cinemas Bakersfield
Dermpathdiagnostics Com Pay Invoice
How To Use Price Chopper Points At Quiktrip
Maria Butina Bikini
Busted Newspaper Zapata Tx
Latest Posts
Article information

Author: Wyatt Volkman LLD

Last Updated:

Views: 6517

Rating: 4.6 / 5 (46 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Wyatt Volkman LLD

Birthday: 1992-02-16

Address: Suite 851 78549 Lubowitz Well, Wardside, TX 98080-8615

Phone: +67618977178100

Job: Manufacturing Director

Hobby: Running, Mountaineering, Inline skating, Writing, Baton twirling, Computer programming, Stone skipping

Introduction: My name is Wyatt Volkman LLD, I am a handsome, rich, comfortable, lively, zealous, graceful, gifted person who loves writing and wants to share my knowledge and understanding with you.