Oh great, now our Twitter data is for sale on the dark web

In case you haven’t been closely following in-depth hacker news feeds (and we don’t blame you if you haven’t), you may have missed an announcement in January from HackerOne detailing a security vulnerability in the Twitter code. The vulnerability let hackers steal phone numbers and emails of users.

Well, a list of millions of Twitter users just showed up for sale on the dark web.

Restore Privacy, a security and privacy watchdog, reported the list of 5.4 million Twitter user emails and phone numbers for sale on a dark web site called Breached Forums. The hacker selling the list claims it contains the private data of “Celebrities, to Companies, randoms, OGs, etc.”

The vulnerability found in January and the sale of personal datasets from Twitter are too closely linked to be mere coincidence.

In January, HackerOne user zhirinovskiy submitted a bug report he had found while analyzing Twitter’s codebase. It was an exploit that could potentially allow a threat actor to access the emails and phone numbers of Twitter users. Although there was no sign of a data breach at the time, zhirinovskiy was concerned.

“This is a serious threat,” zhirinovskiy said in his bug report. “As people can not only find users who have restricted the ability to be found by email/phone number, but any attacker with a basic knowledge of scripting/coding can enumerate a big chunk of the Twitter user base unavailable to enumeration prior (create a database with phone/email to username connections).”

“Thank you for your report @zhirinovksiy,” a Twitter employee named bugtriage_simon replied to the report. “We’re looking into this and will keep you updated when we have additional information. Thank you for thinking of Twitter security.”

The reply came on January 6, five days after zhirinovskiy posted his report.

On January 13, Twitter closed the report and commented: “We consider this issue to be fixed now. Can you please confirm?”

“I can confirm the issue is fixed,” zhirinovskiy replied the same day. Twitter rewarded him for his efforts.

Judging from the exchange of comments on the initial bug report, it took nearly two weeks for Twitter to fix the vulnerability. At some point, a threat actor snuck in and stole 5.4 million datasets. Whether it was done before zhirinovskiy discovered the exploit or after he had posted it remains unknown. What is known is those emails and phone numbers are now for sale.

If your data was included in the breach, you can expect to receive an uptick in spam emails and scammer calls. We recommend using Apple’s Hide My Email if you have iPhone. Also, check out our tips for increasing your online privacy.

Latest posts

Help build a monument to that ‘sad little bitch’ Elon Musk

“Build the perfect monument to force a moment of introspection upon the world’s richest, ugliest little bitch.” | Image: Brendan SMIALOWSKI / AFP via...

Apple trained its own AI model for China with help from Alibaba

Apple has reportedly trained a custom AI model for the China market alongside domestic tech giant Alibaba, a rare cross-border partnership that cuts across...

Hoto’s new cordless soldering iron heats up in three seconds

Hoto is introducing its first soldering iron through its modular Snapbloq collection that lets you assemble your own custom toolbox by stacking magnetic cases...

The MSI Claw EX is the most important handheld since Steam Deck — I still wouldn’t buy one

The Claw EX. I rather like the purple. 3D-printed stand not included. As The Verge's resident handheld reviewer, I have nearly every portable gaming PC...

Trump declares 100 percent tariffs on many drones and all aircraft parts

The United States has already banned future foreign drones from entering the United States unless their companies kiss the ring - as well as...

This school-friendly laptop from HP is $300 off

The HP OmniBook X Flip 2-in-1 converts for tablet or tented use. | Image: The Verge With memory prices still high and showing no signs...

Netflix is closing two game studios

A screenshot of Oxenfree II: Lost Signals from Night School Studio. | Image: Night School / Netflix Netflix plans to shut down two of its...

Microsoft’s Clippy-like Mico character is no longer the face of Copilot

Mico is headed to Learn Live. | Image: Microsoft Microsoft Copilot will no longer show its emotive yellow blob, Mico, when you use the chatbot's...

The fight over Flock and other ALPRs

There are over 120,000 of Flock’s automatic license plate reader (ALPR) cameras installed all over the US. Flock’s cameras, and others like them, use...

‘That is not acceptable’: Judge orders Google to make rival app store installs easier

One month after Epic Games and Google seemingly stopped fighting over the future of Android app distribution, they were back in a San Francisco...