Skip to main content

Oh great, now our Twitter data is for sale on the dark web

In case you haven’t been closely following in-depth hacker news feeds (and we don’t blame you if you haven’t), you may have missed an announcement in January from HackerOne detailing a security vulnerability in the Twitter code. The vulnerability let hackers steal phone numbers and emails of users.

Well, a list of millions of Twitter users just showed up for sale on the dark web.

Recommended Videos

Restore Privacy, a security and privacy watchdog, reported the list of 5.4 million Twitter user emails and phone numbers for sale on a dark web site called Breached Forums. The hacker selling the list claims it contains the private data of “Celebrities, to Companies, randoms, OGs, etc.”

The vulnerability found in January and the sale of personal datasets from Twitter are too closely linked to be mere coincidence.

In January, HackerOne user zhirinovskiy submitted a bug report he had found while analyzing Twitter’s codebase. It was an exploit that could potentially allow a threat actor to access the emails and phone numbers of Twitter users. Although there was no sign of a data breach at the time, zhirinovskiy was concerned.

“This is a serious threat,” zhirinovskiy said in his bug report. “As people can not only find users who have restricted the ability to be found by email/phone number, but any attacker with a basic knowledge of scripting/coding can enumerate a big chunk of the Twitter user base unavailable to enumeration prior (create a database with phone/email to username connections).”

“Thank you for your report @zhirinovksiy,” a Twitter employee named bugtriage_simon replied to the report. “We’re looking into this and will keep you updated when we have additional information. Thank you for thinking of Twitter security.”

The reply came on January 6, five days after zhirinovskiy posted his report.

On January 13, Twitter closed the report and commented: “We consider this issue to be fixed now. Can you please confirm?”

“I can confirm the issue is fixed,” zhirinovskiy replied the same day. Twitter rewarded him for his efforts.

Judging from the exchange of comments on the initial bug report, it took nearly two weeks for Twitter to fix the vulnerability. At some point, a threat actor snuck in and stole 5.4 million datasets. Whether it was done before zhirinovskiy discovered the exploit or after he had posted it remains unknown. What is known is those emails and phone numbers are now for sale.

If your data was included in the breach, you can expect to receive an uptick in spam emails and scammer calls. We recommend using Apple’s Hide My Email if you have iPhone. Also, check out our tips for increasing your online privacy.

Nathan Drescher
Former Digital Trends Contributor
Nathan Drescher is a freelance journalist and writer from Ottawa, Canada. He's been writing about technology from around the…
Nvidia’s RTX 5060 Ti appears in leaked benchmark, and the results are optimistic
Two RTX 4060 graphics cards stacked on top of each other.

If the leaks are to be believed, Nvidia's RTX 5060 Ti is mere days away from launching, set to rival some of the best graphics cards. Today's leaked benchmarks serve as proof that the GPU might indeed be on the imminent horizon, because it showed up in two tests. Both results make me feel a little more optimistic about the RTX 5060 Ti.

VideoCardz spotted Geekbench scores of the RTX 5060 Ti, and while these are synthetic benchmarks that don't say much about the card's ability to handle AAA games, they give us some insight into its specs and overall capability.

Read more
This unique 32-inch LG OLED gaming monitor is on sale at $200 off
Cyberpunk 2077 running on the LG UltraGear Dual Mode OLED.

The 32-inch LG UltraGear Dual Mode OLED gaming monitor is one of the most unique screens that you can buy from today's monitor deals. It's on sale for $1,100, and the $200 in savings on its original price of $1,300 should be considered as a welcome bonus for investing in this display. You're going to have to be quick with your purchase if you don't want to miss this bargain though, as we're not sure how much time is remaining before it disappears.

Why you should buy the 32-inch LG UltraGear Dual Mode OLED gaming monitor

Read more
Grab this reliable 14-inch Dell Inspiron laptop while it’s $300 off
Dell Inspiron 14 Plus 2024 front view showing display and keyboard.

A reliable laptop has become a necessity these days, whether you're a professional or a student. If your current device is no longer able to keep up with you, we highly recommend upgrading to the Dell Inspiron 14 Plus. From its original price of $1,000, it's on sale from Dell with a $300 discount that brings it down to a more affordable $700. You'll enjoy amazing value at this lowered price, but you're going to have to hurry with your purchase as the savings may no longer be available by tomorrow.

Why you should buy the Dell Inspiron 14 Plus laptop

Read more