Data From 235 Million Twitter Users Exposed Online (2024)

A popular hacking platform has published leaked personal data from 235 million Twitter users, which marks the second major Twitter data leak in just two months. The leak left millions of social media users vulnerable with personal information allegedly circulating the dark web.

While some cybersecurity experts claim the data was leaked through an exploited flaw in Twitter’s API (application programming interface), Twitter has denied fault.

The incident leaves many at risk and raises questions about Twitter’s trustworthiness. Although data security was already a major problem under Twitter’s former ownership, Elon Musk inherited an array of challenges with his controversial takeover.

Personal Information of 235 Million Twitter Users Exposed

Data From 235 Million Twitter Users Exposed Online (1)

The email addresses, phone numbers, and Twitter handles of 235 million users were published on a popular hacking platform. The data set included personal information from many public figures, including Donald Trump, Piers Morgan, and Ricky Gervais. It’s now available for anyone to view and download online.

According to Alon Gal, Co-Founder and CTO of Hudson Rock, the data was most likely obtained by a method called “scraping”. In cybercrime, this is when hackers use computer programs or “bots” to extract data with relative ease and little effort.

Gal also denotes the incident “one of the most significant data leaks in history” saying it will “lead to a lot of accounts getting hacked, targeted with phishing, and doxxing.”

The published data also raises concerns about the safety of people using the platform anonymously to speak out against repressive government regimes and corruption.

With Twitter handles published alongside PII (personally identifiable information), outspoken users can be now linked back to their controversial Tweets and comments. In certain countries, this can result in severe consequences including long prison sentences without trial.

The data allegedly came from an exploited API flaw in Twitter’s system. However, Twitter denied this claim in a published report outlining findings from investigations by its incident response team.

According to the report, the exposed information matches data from a leak occurring in July, before Musk’s takeover. In November, the same data was put up for sale for $200,000.

How Will Hackers Exploit Data Leak?

Hackers worldwide will likely seize the opportunity to exploit leaked Twitter data. To protect yourself from the misfortune of falling victim, it can help to know which angles attacks might come from. Here’s a list of the most obvious vulnerabilities:

  1. High-profile accounts. Accounts with many followers are a major target as cybercriminals can use them for spreading malware. If you have a high profile account, change your password and Twitter email address.
  2. Crypto Twitter accounts. Given the financial nature of crypto accounts, they will likely be prime targets for hackers. Cybercriminals will likely prioritize personal accounts associated with high profile cryptocurrency accounts.
  3. Political accounts. Politician accounts are high profile accounts with extra cause for becoming targets. They may be attacked by hackers politically opposed to their views, policies, and ideas.
  4. Doxxing anonymous accounts. Doxxing is the act of revealing personally identifiable information about a person who wishes to stay anonymous. This can be a major problem for people anonymously speaking out against corruption of authoritarian governments.
  5. Social-engineering attacks. Social-engineering attacks use psychological manipulation to gain a victim’s trust before exploiting them. Now hacker’s might have your email address and phone number, pay special attention to contact from unfamiliar persons.

We can’t protect you from social engineering attacks if your data is already on the platform, but we can protect you from hackers and snoopers on your network. CyberGhost VPN uses government-grade encryption to scramble your internet traffic so hackers can’t intercept your data.

Twitter Faces Class-Action Lawsuit For Alleged Exploit

Despite Twitter’s defensive position, one New Yorker is suing the social media company for $5 million in the Northern District of California. The lawsuit launched by Stephen Gerber claims the leak occurred because of an exploit of an API flaw.

Gerber is also accusing Twitter of “burying its head in the sand,” and believes Twitter took deliberate steps to conceal the issue.

The lawsuit is on behalf of everyone affected by the breach and claims peoples’ personal information is now being distributed on the dark web. With stark counter claims from Twitter and the plaintiff, the lawsuit is sure to render interesting results.

Are you a concerned Twitter user and want to know if your data is being sold to cybercriminals? If so, you can visit this website to see whether your personal information is on its database. Please note: results may not be 100% accurate.

Another Stain On Twitter’s Problematic Privacy History

This incident isn’t the first time the social media firm has come under fire for privacy protection concerns. In May 2022, the Federal Trade Commission (FTC) took action against Twitter for “deceptively using account security data to sell targeted ads.” Twitter paid $150 million for the violation and has since been under close scrutiny from the FTC.

In August 2022, Twitter’s former head of security, Peiter Zatko blew the whistle alleging the company deliberately misled regulators about security practices. He also claims the firm neglected addressing disinformation bots on the platform.

While these issues occurred under Twitter’s previous ownership, it doesn’t make them less troublesome for Elon Musk. The new owner has come under fire since his controversial takeover for a number of reasons. While many support his new policies, others have questioned his ability to manage what he calls “the digital town square.”

Is Elon Stepping Down?

Data From 235 Million Twitter Users Exposed Online (2)

On December 19, 2022, Musk launched a poll on Twitter asking “should I step down as head of Twitter?” He also stated he would “abide by the results” of the poll.

After more than 17.5 million votes, a majority of 57.5% voted he should step down. He then stated he’ll resign as CEO when he finds someone “foolish enough to take the job.”

Musk exhibited intentions to step down as head several weeks before in November. He told the courts about his plans to “reduce” his time at Twitter and find someone else to take his position.

Protect Yourself On Twitter

Twitter’s recent history is characterized by extreme turbulence and instability. If you wish to use the platform safely and anonymously, dedicate an email address solely for Twitter use. By making sure it doesn’t have any PII, you can enjoy the platform knowing your activity can’t be linked back to you.

It may also be worth considering Twitter alternatives which are growing in popularity. Twitter is currently a major target for cybercriminals but hackers are less likely to target smaller social platforms.

Consider adding a VPN to your digital toolkit to protect you and your data online. Our state-of-the-art VPN encrypts your internet traffic, minimizing how much information websites collect about you. It also safeguards you from attacks on public Wi-Fi. Get CyberGhost VPN to stay private and in-control of your online data.

Data From 235 Million Twitter Users Exposed Online (2024)

FAQs

Data From 235 Million Twitter Users Exposed Online? ›

Hackers leak email addresses tied to 235 million Twitter accounts. Records of 235 million Twitter accounts and the email addresses used to register them have been posted to an online hacking forum, setting the stage for anonymous handles to be linked to real-world identities.

What was the root cause of the Twitter data breach? ›

Twitter ran into a severe problem at the end of 2022 when it was discovered that the email addresses of millions of users had been leaked. It all started when a critical security flaw, known as a zero-day exploit, was found, putting many Twitter accounts at risk.

What is the Twitter data scandal? ›

What happened in the Twitter data breach? In December 2020, Twitter was fined €450,000 by the Irish Data Protection Commissioner (DPC) for failing to promptly declare and properly document a data breach. This comes after a Twitter bug led to private tweets being made publicly available.

Can I sue Twitter for data breach? ›

When data protection standards have fallen short, and in this case a hack has enabled unauthorised access to your personal data, you can make a claim for compensation. Bringing a data breach claim not only gets you access to compensation, but also holds a company or organisation to account for their actions.

What is the Twitter Bitcoin scandal? ›

The price of bitcoin briefly spiked on Tuesday after a post from the Securities and Exchange Commission's Twitter account claimed that the agency had approved exchanged traded funds to buy and sell the digital currency — a post the agency's chairman subsequently said had occurred because its account on the social media ...

What is the mother of all breaches? ›

The “Mother Of All Breaches,” involving an unprecedented 26 billion records, isn't just a personal concern; it's a corporate crisis. This breach, compromising data from major platforms, poses serious risks to both individual users and organizations. Dive into our mother of all breaches business data security tips.

What was the worst data breach in history? ›

The data breach of Yahoo is one of the worst and most infamous cases of a known cyberattack and currently holds the record for the most people affected. The first attack occurred in 2013, and many more would continue over the next three years.

What does Twitter do with my data? ›

In addition to information you share with us, we use your Tweets, content you've read, Liked, or Retweeted, and other information to determine what topics you're interested in, your age, the languages you speak, and other signals to show you more relevant content.

Is Twitter bad for privacy? ›

In July 2022, Twitter was hacked, and 200 million user email addresses were posted to the dark web. These leaked email addresses can give bad actors information they need to start malicious attacks.

How much compensation do you get for a data breach? ›

For more significant data protection breaches that have resulted in catastrophic repercussions, you can obtain anything from £8,600 to £25,700. If the data breach has caused you bodily or emotional harm, you may be entitled to compensation of up to £42,900.

How do I know if my data has been breached? ›

Bitdefender Digital Identity Protection only needs your email address and phone number to crawl data leaked from breaches to see if your information was exposed. You get a full list of organizations that revealed your details and what type of personal information was exposed.

What happens if you don't report a data breach? ›

Failing to do so can result in heavy fines and penalties and an investigation by the Information Commissioner's Office (ICO).

Who has gone to jail for Bitcoin? ›

Former crypto tycoon Sam Bankman-Fried has been sentenced to 25 years in United States federal prison for stealing $8bn from customers of the now-bankrupt FTX cryptocurrency exchange he founded.

Who is really behind Bitcoin? ›

Bitcoin was created by an anonymous person or group using the pseudonym Satoshi Nakamoto. Nakamoto published a whitepaper titled "Bitcoin: A Peer-to-Peer Electronic Cash System," outlining the concept of a decentralized digital currency.

Why Twitter sued Elon? ›

Mere minutes after Musk took control of Twitter, the former executives say they were fired and that Musk falsely accused them of misconduct and forced them out of Twitter after they sued the billionaire for attempting to renege on his offer to purchase the company.

What is the root cause of data breaches? ›

Although hacking attacks are frequently cited as the leading cause of data breaches, it's often the vulnerability of compromised or weak passwords or personal data that opportunistic hackers exploit.

How did Twitter account get hacked? ›

Twitter hacks can occur when hackers acquire your personal information via data breaches or phishing, but they can also be the result of malware or brute force attacks.

What is the data issue with Twitter? ›

In the past, Twitter has experienced data spills that have led to the disclosure of user information. An outstanding incident is data theft from 400 million users between June 2021 and January 2022. This mass data leak on Twitter resulted from a malicious bug in Twitter's Application Programming Interface.

What caused the data leak? ›

2. How does a data leak happen? A data leak happens when someone from within the organization inadvertently exposes confidential data. It is often the result of outdated systems, poor password policies, stolen or lost devices, and software vulnerabilities.

Top Articles
Latest Posts
Article information

Author: Greg O'Connell

Last Updated:

Views: 5429

Rating: 4.1 / 5 (62 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Greg O'Connell

Birthday: 1992-01-10

Address: Suite 517 2436 Jefferey Pass, Shanitaside, UT 27519

Phone: +2614651609714

Job: Education Developer

Hobby: Cooking, Gambling, Pottery, Shooting, Baseball, Singing, Snowboarding

Introduction: My name is Greg O'Connell, I am a delightful, colorful, talented, kind, lively, modern, tender person who loves writing and wants to share my knowledge and understanding with you.