400 million Twitter users’ data containing private emails and associated phone numbers is said to have been for sale on the black market.
Cybercrime intelligence firm Hudson Rock highlighted a “credible threat” via Twitter on December 24 in which someone is allegedly selling a private database containing contact information for 400 million Twitter user accounts.
“The private database contains devastating amounts of information, including emails and phone numbers of high-profile users such as AOC, Kevin O’Leary, Vitalik Buterin and more,” Hudson Rock stated, before adding:
“In the post, the threat actor claims that the data was obtained in early 2022 due to a vulnerability in Twitter, as well as attempts to pressure Elon Musk to buy the data or face GDPR lawsuits.”[ads1];
Hudson Rock said that while it has not been able to fully verify the hacker’s claims given the number of accounts, it said an “independent verification of the data itself appears to be legitimate.”
BREAKING: Hudson Rock discovered that a credible threat actor is selling 400,000,000 Twitter user data.
The private database contains devastating amounts of information, including emails and phone numbers of high-profile users such as AOC, Kevin O’Leary, Vitalik Buterin and more (1/2). pic.twitter.com/wQU5LLQeE1
— Hudson Rock (@RockHudsonRock) 24 December 2022
Web3 security firm DeFiYield also took a look at 1,000 accounts given as a sample by the hacker and confirmed that the data is “genuine”. It also reached out to the hacker via Telegram and noted that they are active waiting for a buyer there.
If found true, the breach could be a significant cause for concern for crypto Twitter users, especially those operating under a pseudonym.
However, some users have highlighted that such a large breach is hard to believe, given that the current number of active monthly users is reportedly around 450 million.
At the time of writing, the alleged hacker still has a post up Break advertising the database to buyers. It also has a specific call to action for Elon Musk to pay $276 million to avoid having the data sold and being fined by the General Data Protection Regulation agency.
If Musk pays the fee, the hacker says they will delete the data and that it will not be sold to anyone else “to prevent many celebrities and politicians from phishing, crypto scams, sim swapping, Doxxing and other things.”
The data breaches in question are said to have come from the “Zero-Day Hack” on Twitter where an application programming interface vulnerability from June 2021 was exploited before it was patched in January this year. The flaw essentially allowed hackers to scrape private information which they then compiled into databases to sell on the dark web.
Related: Crypto Twitter baffled by SBF’s $250 million bailout and a return to luxury
Alongside this suspected database, two others have previously been identified, with one consisting of around 5.5 million users and another believed to contain as many as 17 million users, according to a report by Bleeping Computer on November 27.
The dangers of having such information leaked online include targeted phishing attempts via text and email, sim swap attacks to get hold of accounts and doxing of private information.
There are some serious concerns with this.
#1 – The identity of many pseudo accounts will be public, posing a risk to them
#2 – With a phone number, it’s super easy to find anyone’s address and bank information.
#3 – Multiple phishing attempts via cell phone, physical or email
– Haseeb Awan – efani.com (@haseeb) 25 December 2022
People are being asked to take precautions such as making sure two-factor authentication settings are turned on for their various accounts, via an app and not their phone number, along with changing their passwords and storing them securely, and also using a private, self-hosted crypto wallet .