Twitter Faces Probe After Data On 400m Users Offered For Sale

Ireland’s data protection office is to investigate an apparent security breach at Twitter after a hacker claimed to offer personal details from 400 million accounts for sale online.

The hacker, using the handle “Ryushi”, offered a sample of details from about 1,000 accounts on  23 December, the same day that Ireland’s Data Protection Commission (DPC) said it would investigate an earlier Twitter breach that affected about 5.4 million accounts.

Both incidents appear to have used the same data-scraping vulnerability, which Twitter said it fixed in January 2022.

Ryushi asked for $200,000 (£166,000) to hand over the data and delete it.

Data breach

The person suggested that it would be in Twitter’s best interests to buy the data itself “exclusively” in order to avoid a large data-protection fine.

The post referred to a 265m euro (£234m) fine the Ireland DPC levied on Facebook parent Meta in November over a data breach affecting about 533 million users.

Ireland’s DPC said it “will examine Twitter’s compliance with data-protection law in relation to that security issue”.

Twitter, which has no press office after it was cut by owner Elon Musk, has not commented on the latest supposed breach.

Celebrity accounts

The small sample of data released so far has included information from the accounts of US politician Alexandria Ocasio-Cortez and broadcaster Piers Morgan.

Computer security firm Hudson Rock, which first brought the latest breach to wider attention, said the hacker’s claim appears credible.

Hudson Rock chief technology officer Alon Gal told the BBC only 60 of the emails in the sampled data appeared in the data from the earlier incident, indicating that “this breach is different and significantly bigger”.

Gal noted that the hacker offered to use an escrow service to sell the data, which would release the funds only if certain conditions are met, another indication in favour of the breach being genuine.

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Craig Wright Sentenced For Contempt Of Court

Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…

2 days ago

El Salvador To Sell Or Discontinue Bitcoin Wallet, After IMF Deal

Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…

2 days ago

UK’s ICO Labels Google ‘Irresponsible’ For Tracking Change

Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…

2 days ago

EU Publishes iOS Interoperability Plans

European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…

3 days ago

Momeni Convicted In Bob Lee Murder

San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…

3 days ago