Skip to content
Mycatalyst
  • Data
  • Business
  • Crypto
  • NFT’s
  • Stocks

Twitter denies responsibility for data leak of 200 million users

January 12, 2023 by mycatalyst.store

For three weeks, a very popular data leak forum has been agitated with the sale then the (almost free) publication ofa database of over 200 million users from Twitter. Each entry in the file contains the name, username, or email address associated with an account, as well as other public information. While this database still consists of relatively low-value data, it is still interesting due to its gigantic volume.

The social network and its leader Elon Musk -usually very talkative- have refrained from commenting on these events… until yesterday. The User Privacy Team said in a statement that after analyzing the published database, they found ” no evidence that the data sold online was obtained through a flaw in Twitter’s systems. »

Twitter: 4 questions about data leaks from over 200 million users

A dubious hypothesis to avoid fines

Twitter suggests that the people behind the file release may have only been doing data enrichment, a practice that involves cross-referencing different databases. Concretely, they would have collected public data from Twitter such as usernames, display names or account creation dates, but then simply cross-referenced it with other datasets to associate them with email addresses. With this hypothesis, the social network declines any responsibility for the leakage of personal data, which would expose it to fines in different legislations, and in particular in Europe with the RGPD.

However, Alon Gal, a reputable data leak analyst at Hudson Rock, questions Twitter’s theory of his LinkedIn account. For him, the authenticity of the leak is evident from the absence of false positives in the file’s account/email associations, which are common in cases of simple enrichment. Other analysts confirm these observations, but it remains difficult to identify the origin of the data with certainty.

The social network also rightly points out that the database does not contain any passwords or other data that would make it possible to become one, which drastically reduces its danger to the integrity of Twitter accounts.

The hypothesis of the use of a defect is not excluded

The people behind the release of the file said they exploited a vulnerability in the way the API works [l’interface de connexion avec d’autres sites, ndlr] of Twitter, at the end of 2021. In August 2022, the social network – which was not yet under the control of Elon Musk – had recognized the existence of this bug, reassembled by an ethical hacker in January and corrected immediately.

When an API user submitted an email address, the API returned the associated account, which it shouldn’t have done. It was enough to repeat the operation using the mailing lists, of which hundreds circulate on unscrupulous forums to build a database. In other words, Twitter did not leak personal data (email address) but allowed to associate them with an account. Fortunately, this association is not sufficient to connect to the accounts, since the password is needed as well as the double authentication code if activated. On the other hand, it allows malicious individuals to target accounts of interest (personalities, companies, etc.) with phishing [messages piégeux, ndlr] personalized, hoping to steal this information from them.

This summer Twitter had confirmed the link between this bug and the publication of a database of 5.4 million users during the summer. But the new administration says the 200 million user base would not be tied to it. ” We have not been able to correlate the new data with that of the previous incident “, Indicates the social network in its press release.

Twitter in the sights of regulators

However, Twitter has not communicated directly with users affected by this summer’s leak, nor does it intend to notify those affected by the recent leak. The American regulator –the Federal Trade Commission– And the Irish Data Authority – where Twitter’s European headquarters are located – have both opened investigations into the incidents, and more generally into the security of the social network. Following the Elon Musk takeover in late October, no less than three executives responsible for Twitter’s security and data integrity have resigned, without being replaced.

As a reminder, Facebook’s parent company Meta was fined €275 million in Europe for violating the GDPR, following the publication of a similar database (with phone numbers instead of email addresses) in 2021 .

Categories Data Tags acher stock, achr stock news, amway business, android data storage, android data store, android storage data, android store data, android storing data, archer aerospace stock, archer stock, archer stock price, archer stocks, archery stock, bank of america can't stop banking, business amway, business management domain_9, business manager domain_9, business outlet dell, business tiktok center, can't stop banking, chrome business, chrome for business, data in finance, data storage android, data storage in android, dell business clearance, dell business login, dell data vault, dell data vault collector, dell outlet business, dell quote stock, dell small business outlet, dell stock quote, domain_9 business manager, ee business ipad, ee business mobile contract, ee business tablets, ftx business account, ftx gold advantage, gmail business email with your domain, gold flatware rental near me, gold silverware rental near me, joby stock forecast 2025, joby stock forecast 2030, keiser university graduation dates 2022, keiser university graduation dates 2023, linked business manager, linked in business manager, logicmonitor stock price, mongodb stock price today, register verizon business account, room data base, stock price mongodb, stock quote dell, store data android, store data in android, storing data in android, telus mobility business plans alberta, verizon wireless small business account, verizon.com/business/plans, vzw business support, what is dell data vault, what is dell data vault data collector
EcoRéseau Business – The political eye – Brigitte Macron, the other president
Factbox: The many companies in the Digital Currency Group’s crypto empire

Leave a Comment Cancel reply

Recent Posts

  • Nearly 500 million people’s data was compromised in 2022, half of them on the same site
  • BioSenic appoints Yves Sagot as Independent Director
  • controversial a video sent to officials, the CNIL “investigates the complaints”
  • US inflation data in line with expectations of limited Fed action
  • The Paris Stock Exchange closes slowly, central banks in sight – 01/27/2023 at 18:53

Recent Comments

No comments to show.
  • Privacy Policy
  • About US
  • contact us
  • DMCA
  • Terms and Conditions
© 2023 Mycatalyst • Built with GeneratePress
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT