Twitter claims that the most recent user data leak is from the 2021 breach

Share post:

Twitter has affirmed that the latest leak of millions of members’ profiles, such as private phone numbers and email addresses, was caused by the same data breach divulged by the company in August 2022.

In 2021, a vulnerability in Twitter’s API caused a data leak that exposed private user profile information, affecting at least 5.4 million of the platform’s estimated 200 to 300 million users (at the time). The information is now freely available on a dark web forum.

Several parties were allegedly able to access the API by entering phone numbers and email addresses; matches to an account returned non-public contact and platform use information. The API flaw allows an attacker to enter email addresses or phone numbers to obtain a Twitter ID for a registered account. Twitter is said to have patched the security flaw in January 2022.

In July 2022, the contents of the data leak were first listed for sale on an underground forum, with one of the hackers asking $30,000 for a collection of 5.4 million Twitter user files. The API flaw exposed the account’s email address and phone number, as well as the city the user lives in (if provided) and some non-public usage and engagement metrics.

While Twitter’s most recent update indicates that the data leaked last month is related to the recently reported vulnerability, the company has not revealed the exact number of users who were exposed.

The sources for this piece include an article in BleepingComputer.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Apple reduces forecasts for Vision Pro as demand cools in key US market

In an unexpected shift, Apple has drastically reduced its shipment forecasts for the upcoming Vision Pro, indicating a...

FTC says Microsoft’s layoffs at Activision Blizzard may threaten merger approval

The FTC has expressed dissatisfaction with Microsoft's layoffs at Activision Blizzard, challenging the integrity of the Microsoft-Activision deal....

Delaware court voids Musks $56 billion dollar compensation

Tesla's stock experienced a notable downturn following a Delaware court's decision to void CEO Elon Musk's massive $56...

IT World Canada strikes partnership with Canadian Cybersecurity Network

Goal is to make it easier for infosec pros to access each organization

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways