/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Twitter says that the company's investigation found “no evidence” that its users' data sold online was obtained by exploiting vulnerabilities in its systems

Todd Spangler / Variety :

Variety Todd Spangler

Context & Ripple Effects

Twitter's 'no evidence' finding lands in a long line of incidents where user data surfaces online without a confirmed breach of Twitter itself: the company made a nearly identical claim after millions of usernames and passwords appeared online in 2016, and again in 2020 when it locked recently-reset accounts while saying hackers never got passwords.

What makes this round different is the known alternative source: in August 2022 Twitter confirmed a now-patched bug let attackers link phone numbers and emails to accounts, and a threat actor offered 5.4M such records for sale — so the company can plausibly attribute the sold data to third-party abuse rather than its own systems, while an FTC review of the 'Twitter Files' episode keeps the company's data-security compliance under active regulatory attention.

First-order effects

  • Users whose contact details are circulating for sale get no breach notification or remediation from Twitter, since the company's finding means no reportable compromise of its own systems.
  • Twitter avoids the legal and disclosure obligations that would follow from admitting a vulnerability exploit, keeping the 2022 phone/email-linking bug as the presumed origin story for the sold records.

Second-order effects

  • Security researchers who traced the 5.4M-record listing will keep pressing on where else the data could have come from, since a self-conducted investigation with a negative result invites independent replication rather than closing the question.
  • Regulators holding Twitter's data-security order gain another data point in the pattern of self-audited 'no evidence' outcomes, strengthening the case for externally verified audits rather than company-run investigations.

Third-order effects

  • If platforms keep resolving leak controversies through internal investigations that find no fault, accountability for scraped and resold user data shifts toward third parties — data brokers and threat actors — leaving the original platforms structurally insulated from liability unless outside auditors or regulators force provenance questions into the open.

The trend: Major social platforms are increasingly attributing leaked user data to third-party scraping and aggregation rather than their own breaches, making self-investigation the default accountability mechanism.

Discussion

  • Privacy Privacy on x
    Update about an alleged incident regarding Twitter user data being sold online
  • @carnage4life Dare Obasanjo on x
    Twitter has stated that hackers selling databases of email addresses of hundreds of millions of Twitter users are lying that the data was hacked from Twitter. This is a bold gambit given what happened with LastPass downplaying then walking back a hack. https://variety.com/...