Twitter fixed an API vulnerability back in January 2022, but it now seems hackers stole 5.4 million active users’ data before the patch. More than 7 million accounts in total were breached, with 1.4 million of those being inactive. Not quite the news that Twitter needed to hit the market, after a tumultuous time since the Elon Musk takeover.
Read: Deadly robots could be let loose in San Francisco
According to the security research done by Bleeping Computer, there may be an additional, more significant data dump of millions of Twitter accounts that contain non-public information, including phone numbers and email addresses. In July 2022, a malicious actor started trying to sell the 7 million Twitter users’ private information — which they obtained by exploiting the API vulnerability — on the Breached hacking forum.
The reports explain how the breach worked, with the malicious actors simply entering a phone number and email address into the API to get associated Twitter IDs, which they could then use to scrape further information. Twitter said that it was aware of the breach and the API flaw was secured in January. It also added that not sensitive personal information was compromised, but that doesn’t seem to be the case anymore.
Pompompurin, a hacking group that owns the Breached hacking forum, has come forward as the responsible party for the breach. It created the massive dump of Twitter user information, which it said is now being shared for free on its hacking platform.
The second, larger data breach took place on Wednesday, November 23rd, according to security researcher Chad Loder. While the data includes similar information, the breach is far more widespread, affecting all Twitter accounts that have the “Let others find you by your phone” discoverability feature enabled.
“I have just received evidence of a massive Twitter data breach affecting millions of Twitter accounts in EU and US,” Loder said. “I have contacted a sample of the affected accounts and they confirmed that the breached data is accurate. This breach occurred no earlier than 2021.”



