Hacker claims to be selling Twitter data of 400 million users
https://www.bleepingcomputer.com/news/security/hacker-claims-to-be-selling-twitter-data-of-400-million-users/


If you are also using a Steam or game-related email address on Twitter, please prepare a new one and change it.๐Ÿ™„


How to Protect Yourself After the Latest Alleged Twitter Data Breach
https://www.msn.com/en-us/money/other/how-to-protect-yourself-after-the-latest-alleged-twitter-data-breach/ar-AA15JVMb
(omit)

How Can You Protect Yourself After the Alleged Twitter Breach?

While there is no confirmation that the information will be released to private buyers, or if it is even genuine, it can potentially be used by criminals to help target you. If you use your email address for any other account, you should change it on those accounts immediately. Likewise, you should unlink the telephone number used for your Twitter account from any other accounts.

Going forwards, you should use email aliasing for any account you sign up to, and where possible, use a secondary phone number. SMS or phone-based 2FA systems have long been considered insecure, and you should move to app-based 2FA instead.

(omit)


Note that the data was probably collected prior to January 2022, so even if you think you are safe because you were exiting Twitter, please be careful.

What happens next will depend on "Elon".๐Ÿ˜ท
What will happen? What do you think?๐Ÿค
I don't have a Twitter account. So I don't know.๐Ÿ™„


Update 1

200 million Twitter users' email addresses allegedly leaked online
https://www.bleepingcomputer.com/news/security/200-million-twitter-users-email-addresses-allegedly-leaked-online/


๐Ÿคฆโ€โ™€๐Ÿคฆโ€โ™‚โˆ‘(ใƒŽฮ˜`*)
Incidentally, this list seems to have been added to the leak confirmation site.

Have I Been Pwned: Check if your email has been compromised in a data breach
https://haveibeenpwned.com/

Update 2

Are you hate ..HIBP?

Firefox Monitor
https://monitor.firefox.com/

Update 3

Update about an alleged incident regarding Twitter user data being sold online
https://privacy.twitter.com/en/blog/2023/update-about-an-alleged-incident-regarding-twitter-user-data-being-sold-online

Twitter claims leaked data of 200M users not stolen from its systems
https://www.bleepingcomputer.com/news/security/twitter-claims-leaked-data-of-200m-users-not-stolen-from-its-systems/

Twitter says no evidence new user data leaks were obtained via system bug | Reuters
https://www.reuters.com/technology/twitter-says-no-evidence-that-data-being-sold-obtained-by-its-systems-2023-01-11/


CNN
Brian Fung | @b_fung@masto.ai on Twitter: "I'm a little confused by what Twitter is trying to say here. Is it just "we compared the 400m/200m dataset with the previously leaked 5.4m dataset and found no overlap, thus there's 'no evidence'" that it came from the API bug?" / Twitter
https://twitter.com/b_fung/status/1613269708907909120


1 year ago*

Comment has been collapsed.

Was this information meaningful?

View Results
Yes, I found it useful.๐Ÿค—
No, I did not.๐Ÿšฎ
Yes No I also give cucumbers.=อžอŸอŸอž( ใฃ'ฯ‰')โ•ฎ=อžอŸอŸอž๐Ÿฅ’ใ€€๐Ÿ˜‹
No, I would not. Requests potato.=อžอŸอŸอž( ใฃ'ฯ‰')โ•ฎ =อžอŸอŸอž๐Ÿฅ”ใ€€๐Ÿ˜ซ

Got an email from haveibeenpawned. Breach happened in 2021.

1 year ago
Permalink

Comment has been collapsed.

haveibeenpawned

Have I Been Pwned: Check if your email has been compromised in a data breach
https://haveibeenpwned.com/

(o'ฮ˜'))Perhaps the scope of impact and detection will expand in the future.
For now, as long as it is changed before it is abused, there will be no problem...maybe.

1 year ago
Permalink

Comment has been collapsed.

Just change password for main email, and I always suggest have different password for different accounts.

1 year ago
Permalink

Comment has been collapsed.

I generally agree with you.
Sometimes people log in with "Twitter" or "Google" accounts, and those people have a wider range of damage impact during these incidents.

1 year ago
Permalink

Comment has been collapsed.

why would i change my email address and phone number though?

1 year ago
Permalink

Comment has been collapsed.

General Reasons
To avoid receiving fraudulent phone calls or phishing scam emails in the future.

Malicious Reason
To use one of the information items obtained to exploit another vulnerability and use it as a feeding ground for periodic exploitation.
(This is an easy target because it is approximately what is important is tied to it.)
(When a vulnerability is found that allows a password to be bypassed with the email address known, there's a possibility that the contents could be easily stolen.)

Of course, when changing phone numbers, the level of difficulty varies from country to country.
However, e-mail addresses are relatively easy to create, so it is a good idea to transfer from one that can be discarded in case of emergency.

In any case, you should at least change your password.


[tale overflowing with stories]
A scam I recently heard about....

Workers from China receive a call from mainland China telling them to come back because criminal penalties will be applied.
They get calls asking them to deposit money because if they give a bribe, it will be pretended that it never happened.

If this were a migrant worker from a common country, they would not care. If they receive such a call in their native language, they can simply ask the embassy to call them back.

But for Chinese citizens who have their own police closely attached to their own embassies in other countries, who ignore international law, and who bring their own laws to other countries to crack down on them, this sounds like the real thing, not a scam.

Well, stories similar to this are becoming more conspicuous lately in countries where the home country is corrupt.
Perhaps such a large leak of information could be used to select targets for such an action.
These are scary times.

1 year ago
Permalink

Comment has been collapsed.

For what it's worth, changing the email/phone now after the breach won't do a single thing to stop spam emails/calls as that data has already been leaked. All you'll be doing is just making sure for the next breach, more information will get leaked so you'll get even more spam/scams sent your way through more avenues.

1 year ago
Permalink

Comment has been collapsed.

I am too old for twitter,insta,snapchat,facebook i dont use any of these :)

1 year ago
Permalink

Comment has been collapsed.

You are probably still in good health when you are using this place.๐Ÿ˜‰
I'll have this done where the information was leaked, so that's okay....
[Flash Warning]

View attached image.
1 year ago
Permalink

Comment has been collapsed.

UPDATE

200 million Twitter users' email addresses allegedly leaked online
https://www.bleepingcomputer.com/news/security/200-million-twitter-users-email-addresses-allegedly-leaked-online/

๐Ÿคฆโ€โ™€๐Ÿคฆโ€โ™‚โˆ‘(ใƒŽฮ˜`*)
Incidentally, this list seems to have been added to the leak confirmation site.

Have I Been Pwned: Check if your email has been compromised in a data breach
https://haveibeenpwned.com/

1 year ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 4 months ago.

1 year ago
Permalink

Comment has been collapsed.

If you are entering unimportant information that can be leaked, I feel that this is still fine.๐Ÿ™„
(Or if you are preparing to lock, restore, or recover means.)
Is it a trend nowadays that every time there are more password leak notices, there are more new spells...?๐Ÿง™LvUP๐Ÿงš

If not, or if this is the first time a human being has been leaked, I feel it is a big deal.(๏พ‰ฮ˜`)

1 year ago
Permalink

Comment has been collapsed.

where possible, use a secondary phone number

And this is why mandatory phone 2FA or more generally mandatory phone number is toxic as hell. Never gave my phone number to Twitter nor Discord, despite all the trouble they made me go through for refusing to do so.

1 year ago
Permalink

Comment has been collapsed.

I really like when companies try to make it look impossible to buy something without saving CC details on website. At least when it's possible to remove CC later from account settings...

1 year ago
Permalink

Comment has been collapsed.

Twitter (200M): In early 2023, over 200M records scraped from Twitter appeared on a popular hacking forum. The data was obtained sometime in 2021 by abusing an API that enabled email addresses to be resolved to Twitter profiles. The subsequent results were then composed into a corpus of data containing email addresses alongside public Twitter profile information including names, usernames and follower counts.
Compromised data: Email addresses, Names, Social media profiles, Usernames

No passwords.

1 year ago
Permalink

Comment has been collapsed.

That is true for the 400 million and the separate 200 million cases.
The 400 million items would also be "phone number" and "email address" that would fall under personal information.

In fact, even if password information was also compromised, that is something that would not be sold, and there is a good chance that they would prey on users who do not change their passwords.
(I'm talking about a case-by-case basis.)

That would not be a reason not to change the password.

*Number typo fix

1 year ago*
Permalink

Comment has been collapsed.

For the lazy ones, you dont need to change to a new email. Just change the password for the leaked site and any other sites that reuse the same password. While you are at it, it is best if you try using different password for different websites.

1 year ago
Permalink

Comment has been collapsed.

The world is full of things that exceed expectations.๐Ÿ™„
The very good!ใ€€Or very bad!

If there is an unscrupulous person in this world who has the same password for all of his/her email accounts and passwords for various services, let us pray that he/she will start by changing the passwords for his/her email accounts.๐Ÿ™๐Ÿ›๐Ÿคฒ๐Ÿ˜จ

1 year ago
Permalink

Comment has been collapsed.

laughs in never made a twitter

1 year ago
Permalink

Comment has been collapsed.

i dont care, what if they have my email and random password? they can send spam, i will block it, done

1 year ago
Permalink

Comment has been collapsed.

Thank god I'm not a twit. I mean twitter user.

1 year ago
Permalink

Comment has been collapsed.

I said all the time that twitter is easy to hack and a risk.... so not really a surpise for me.

I use it only for a few GAs, with my third mailadress (they can send me spam that i, most likely will never see before it gets automaticly deleted :-D) -made for sites where i expect to get spammed (or things like stolen datas), a other user name that i used only on one site before (a trash one, years ago), with a password that i use only for twitter (i use on each site a other password, so good luck trying one of them on a other site -muhahahahahaha- :-D), oh and they don't have private data from me.

So all cool, nothing unexpected or serious.

1 year ago
Permalink

Comment has been collapsed.

At least I spend a week last year to go through all websites I registered in past 20 years, and generated new passwords with Bitwarden!

https://arstechnica.com/information-technology/2022/12/lastpass-says-hackers-have-obtained-vault-data-and-a-wealth-of-customer-info/

LastPass, one of the leading password managers, said that hackers obtained a wealth of personal information belonging to its customers as well as encrypted and cryptographically hashed passwords and other data stored in customer vaults.

Oh welp.

1 year ago
Permalink

Comment has been collapsed.

Wow.. smh

1 year ago
Permalink

Comment has been collapsed.

Oh, there was a story about that.
I feel like the key ring called "password manager" is usually the gateway to hell.
I have the same feeling about the button people use to save their browser passwords.

I think there was a recent scare about security software mis-detecting and deleting harmless files.
(Some hacker peppered the virus definition files)

I felt the importance of making backups....๐Ÿ™„

1 year ago
Permalink

Comment has been collapsed.

I felt the importance of making backups....๐Ÿ™„

And I really should start to make them more regularly.

1 year ago
Permalink

Comment has been collapsed.

Thanks a lot Kappa, if you hadn't made this thread I wouldn't have changed my passwords. My email was mentioned in the current leak, and a few more times in past years :(

1 year ago
Permalink

Comment has been collapsed.

The older the problem, the more you have to suspect the shadow of an evil entity that claims to be you without your knowledge.
It's frightening, isn't it?โˆ‘(ยดฮ˜`)
I hope nothing serious happened.

1 year ago
Permalink

Comment has been collapsed.

As long as any sites that are attacked do not receive any fines from DPA (Data Protection Authority), these leaks will continue...
Although I've had my account for several years, I've only made 2 tweets, so even if I delete it, I don't mind.

1 year ago
Permalink

Comment has been collapsed.

Personally...
I am more afraid of those who purport to "collect fines for information leaks," restricting information dissemination or confiscating information under the guise of auditing.
In any case, it is worth noting that different countries have different attitudes toward these efforts.
In one country, there was so much distrust of personal computers that, until recently, people trusted faxes more than personal computers.
Then, forcibly assign a national number to organize the information. (For things to get better)
Even if we agree with the "purpose" of the system, the implementation is so garbage that the country is about to become a hotbed of information leakage.... It's not funny.

In any case, if those two accounts don't have any information tied to anything else, I guess the choice would be not to care.๐Ÿค”

1 year ago
Permalink

Comment has been collapsed.

I agree with what you say, but I speak as a member of Europe, where restrictions and sanctions still exist (but again it varies from country to country). And I think that these fines are returned to the countries that impose them.

Speaking of privacy, in my country the government was caught spying on a leader of another party (as well as other politicians and journalists), and as funny as it sounds, it's still the government.

I was more scared about my email, because I've had it for many-many years and of course I use 2fa everywhere, so just with the password, I don't know if they can easily gain access.

1 year ago
Permalink

Comment has been collapsed.

2FA will be safe.
Unless someone borrows your smartphone for a short time.

Somewhere in the world, an evil family member will have backed up the 2FA authentication app, deleted the migration notification from the email app, and handled it as if nothing had happened. In this case, that person will have more smartphones displaying the same authentication code.
Android? https://myaccount.google.com/security-checkup
If such an action is taken, the person's e-mail will not be notified, and you will not be aware of such a case unless you check this kind of security check page to see if there are more terminals that you do not know about.
It's not a bad idea to pay attention from time to time to see if you might be involved in something terrible that you don't know about.
Some people even set their browser's startup page.
For those who don't trust Google, it's a pain, but Android has increased too much.๐Ÿค–

1 year ago
Permalink

Comment has been collapsed.

I'm more afraid of the leaks from the mobile phone companies, that even though I've made my mobile extra private, I always get phone calls about offers I'm not interested in. When asked how they got my number, they say it came from a RNG... seems like I'm very lucky that my number comes up every few days.
My google account is safe. At least that's how it looks. :)

1 year ago
Permalink

Comment has been collapsed.

Good thing I have been off Twitter since 2016 after a brief period of mild curiosity.
Still good to read about this in case it affects anyone around here though.
Thanks Kappa :)

1 year ago
Permalink

Comment has been collapsed.

Personally, I am more afraid of Facebook and Tiktok, but it seems that the world attracts people who want to do bad things where people gather.
Does the blue bird live in the Tower of Babel? I wonder.

1 year ago
Permalink

Comment has been collapsed.

im banned on twitter so there is no way for me to delete my account

1 year ago
Permalink

Comment has been collapsed.

im banned on twitte

On Twitter, it appears that if you are banned, you can only "log in" and "read".

You can start deleting your account from Settings and Privacy.
It is supposed to disappear in 30 days after initiation.
(Not sure if this is true or not)

1 year ago
Permalink

Comment has been collapsed.

I have tried to do that before I get this noti " Your account is suspended and is not permitted to perform this action. "

1 year ago
Permalink

Comment has been collapsed.

https://help.twitter.com/en/managing-your-account/suspended-twitter-accounts#how-to-deactivate-suspended-account
Hmm...
It seems to take this kind of time and effort when that indication appears. For your information.

1 year ago
Permalink

Comment has been collapsed.

Yah I have read and tried to send a ticked form this link https://help.twitter.com/en/forms/account-access/appeals and still it didnt work twitter just sucks

1 year ago
Permalink

Comment has been collapsed.

Is support closed in the aftermath of the recent Elon reform?ใ€€It's a mystery. It would not be a very good thing.๐Ÿค”๐Ÿ˜ฏ

1 year ago
Permalink

Comment has been collapsed.

It's not, I got my account back after several appeals and It was perma banned because some douche from Turkey managed to access It and started promoting NFT's and using bot followers or something like that to inflate other accounts. I can't confirm but It seems that if you get perma banned and create another one from the same device you will get perma again.

1 year ago
Permalink

Comment has been collapsed.

can confirm got all my alts banned / any new account banned

1 year ago
Permalink

Comment has been collapsed.

Try every month with your request as the subject, It may take a while but be persistent with the appeals, you also need to confirm that you have access to that e-mail, they will send you a confirmation e-mail for that.

1 year ago
Permalink

Comment has been collapsed.

Is been like 5 months now but I will try to send a appeal everytime they reject it

1 year ago
Permalink

Comment has been collapsed.

I appreciate you bringing this to our attention! It's very helpful.

Thank god I have different passwords for each of my accounts, because it's less likely that someone will fuck with my other accounts. But even then, it's still stressful, because of the what ifs. Fuck this nonsense.

1 year ago
Permalink

Comment has been collapsed.

Even if we are prepared for information leaks, we end up feeling like we have ice water poured down our backs because even if we are okay, those around us may have a hard time.๐Ÿ˜ญ

By the way, if my information is leaked, rest assured that at best I will be thought of as a lunatic who got it wrong in his head with E.T.
The recovery team should not come from Area 51 because of the hassle. (Maybe.

Information leakage, everyone is not afraid if they are exposed.
This is also true if you are not doing sinful deeds on a daily basis.
(Unless, perhaps, I'm after the cucumbers of mankind.)

View attached image.
1 year ago
Permalink

Comment has been collapsed.

even if we are okay, those around us may have a hard time. ๐Ÿ˜ญ

Yeah. ๐Ÿ˜ญ My mom uses bad passwords everywhere, and I do worry about her. I've been trying to get her to at least use password managers.
It's all very stressful.

1 year ago
Permalink

Comment has been collapsed.

It is also troubling that it is becoming increasingly difficult to determine whether or not the person did this when the "leaked information" is finally blurred, or if an evil stranger has used the "leaked information" to "register" for a new service in general.

Eh? Is it pornography? Oh, the old man had a habit of looking for free videos.
I don't use them. You can trust me!
Really?
Are you saying that your computer was hijacked and you watched it without your permission?
Well...

When these old man are your relatives, it is no wonder you worship the god of the Cthulhu Mythos or attempt to summon the spaghetti monster.๐Ÿ๐Ÿ™๏ฝก๏พŸ(๏ฝกpฮ˜q๏ฝก)๏พŸ๏ฝก๐Ÿ˜ญ

1 year ago
Permalink

Comment has been collapsed.

Update 2

๐Ÿ™„By the way, some of you did not want to use "HIBP", so I have attached the Firefox version.
Of course, if you want to check with both, you can do so.

Firefox Monitor
https://monitor.firefox.com/

1 year ago
Permalink

Comment has been collapsed.

Closed 1 year ago by Kappaking.