5.4 mn Twitter users' data leaked online
Further, there were additional 1.4 mn Twitter profiles collected using a different Twitter application programming interface (API) that have reportedly been shared privately among a few people
image for illustrative purpose
New Delhi: As Elon Musk goes gaga over Twitter 2.0, which will be the 'Everything App', at least 5.4 million Twitter user records, stolen via an internal bug, have been leaked online on a hacker forum.
In addition to the 5.4 million records for sale online, there were an additional 1.4 million Twitter profiles collected using a different Twitter application programming interface (API) that have reportedly been shared privately among a few people.
The massive data consists of scraped public information as well as private phone numbers and email addresses that are not meant to be public, reports Bleeping Computer. The data expose came at a time as Musk revealed his Twitter 2.0 -- The Everything App, saying that the new user signups are at an all-time high and the company is now actively recruiting.
Security expert Chad Loder first broke the news on Twitter and was suspended soon from the platform.
"I have just received evidence of a massive Twitter data breach affecting millions of Twitter accounts in the EU and the US. I have contacted a sample of the affected accounts and they confirmed that the breached data is accurate. This breach occurred no earlier than 2021," Loder had posted on Twitter.
The data containing non-public information was stolen using a Twitter API vulnerability fix in January this year.
This data was collected in December 2021 using a Twitter API vulnerability disclosed in the HackerOne bug bounty programme, the report said on Sunday.
Most of the data consisted of public information, such as Twitter IDs, names, login names, locations, and verified status.