A hacker leaks a dataset allegedly containing the email addresses of 200M+ Twitter users, claimed to be a cleaner version of the 400M dataset from December 2022
A data leak described as containing email addresses for over 200 million Twitter users has been published on a popular hacker forum for about $2.
BleepingComputerLawrence Abrams
Context & Ripple Effects
Twitter had already confirmed that a now-patched flaw could connect contact details to accounts, after a threat actor offered 5.4 million linked user records for sale. The newly published file is alleged to be a more usable edition of a much larger December dataset, making the earlier incident’s exposure claim materially more consequential.
Twitter has also faced earlier reports of usernames and passwords appearing online, although it said those credentials were not taken from its systems. The recurring issue is the durability of account-identity data once it enters criminal distribution channels.
First-order effects
People whose email addresses are accurately matched to Twitter accounts face more targeted phishing and account-impersonation attempts, while the low reported price makes the file broadly accessible.
Twitter must contend with renewed scrutiny of the patched contact-discovery flaw because the file is presented as a cleaned-up derivative of the earlier dataset.
Second-order effects
Attackers can combine email-to-account mappings with previously exposed credentials or public profiles, increasing the value of older breach material without requiring a new intrusion.
Other consumer platforms that expose account discovery through contact information face pressure to reassess whether those features create durable identity-linkage risks.
Third-order effects
Repeated resale of account-linkage datasets shifts breach harm from a one-time incident to a persistent identity-data supply chain, where cleanup by the original platform cannot retract copies already distributed.
The pattern strengthens the case for treating public-account discovery and contact matching as a long-lived personal-data exposure rather than a narrow product-security setting.
The trend: Consumer platforms are increasingly judged by how long account-identity data remains exploitable after an underlying vulnerability has been fixed.
Somewhat good news. The data does NOT include phone numbers after all. The hacker who advertised the 400M+ leak last month included a small sample of the data with phone numbers. …
""This database is going to be used by hackers, political hacktivists and of course governments to harm our privacy even further," said Alon Gal, co-founder of the Israeli security company Hudson Rock" 🎩@TeresaCCarter2 ; https://www.washingtonpost.com/ ...
“While Elon Musk previously used @dotMudge's testimony about poor security practices in a failed attempt to get out of buying the company, he has since laid off many of its security staffers.” https://twitter.com/... https://twitter.com/...
“In July, hackers were spotted selling a set of 5.4 million Twitter account handles and associated emails and phone numbers, which Twitter said was the first it learned that someone had taken advantage of the flaw.” The article without a paywall here: https://www.washingtonpost.c…
In 2021, multiple threat actors abused a Twitter API flaw to associate email addresses or phone numbers with Twitter IDs. Another API was then used to scrape public data for these IDs to create Twitter user profiles. This flaw was fixed in January 2022.
Records of 235 million Twitter accounts have been posted to an online hacking forum, setting the stage for anonymous handles to be linked to real-world identities. Researchers believe the hackers exploited a flaw in Twitter's internal verification system. https://www.washingtonpo…
Well done Twitter. Thousands upon thousands of anonymous users living under authoritarian regimes thank you for your commitment to trust and safety. Power to the people. https://www.washingtonpost.com/ ...
The Saga of the API vulnerability fixed in Jan 2022 continues, with a threat actor leaking a data set allegedly containing email addresses for 200 million profiles basically for free on a hacking/data breach forum.
According to securityaffairs, a user posted a file on the Breach forum containing the data of 235 million Twitter users, which can be downloaded for just 8 credits. Hackers may use crypto accounts as important targets for phishing or related attacks. https://securityaffairs.com/ …
Your email address & that of 199,999,999 other #Twitter users on sale now for the bargain basement price of $US2.00. #TwitterDown #cybersecurity #privacy https://www.bleepingcomputer.com/ ...
Millions of Twitter users could face exposure if they were anonymous, hundreds of millions could face account takeover attempts. https://www.washingtonpost.com/ ...
Since then, scrapers have been selling/circulating large collections of Twitter data throughout 2022, including a 5.4 million data set, a 17 million set, and now the 200 million line data set. Each of these sets were formatted differently from samples seen by BleepingComputer.