Â鶹ӰÊÓ

Skip to main content

Twitter breach exposed anonymous account owners

Share

A vulnerability in Twitter's software that exposed an undetermined number of owners of anonymous accounts to potential identity compromise last year was apparently exploited by a malicious actor, the social media company said Friday.

It did not confirm a report that data on 5.4 million users was offered for sale online as a result but said users worldwide were affected.

The breach is especially worrisome because many Twitter account owners, including human rights activists, do not disclose their identities in their profiles for security reasons that include fear of persecution by repressive authorities.

"This is very bad for many who use pseudonymous Twitter accounts," U.S. Naval Academy data security expert Jeff Kosseff .

The vulnerability allowed someone to determine during log-in whether a particular phone number or email address was tied to an existing Twitter account, thereby revealing account owners, the company said.

Twitter said it did not know how many users may have been affected, and stressed that no passwords were exposed.

"We can confirm the impact was global," a Twitter spokesperson said via email. "We cannot determine exactly how many accounts were impacted or the location of the account holders."

Twitter's acknowledgment in a blog post Friday followed detailing how data presumably obtained from the vulnerability was being sold on a popular hacking forum for US$30,000.

A security researcher discovered the flaw in January, informed Twitter and was paid a reported US$5,000 bounty. Twitter said the bug, introduced in a June 2021 software update, was immediately fixed.

Twitter said it learned about the data sale on the hacking forum from media reports and "confirmed that a bad actor had taken advantage of the issue before it was addressed."

It said it was directly notifying all account owners that it can confirm were affected.

"We are publishing this update because we aren't able to confirm every account that was potentially impacted, and are particularly mindful of people with pseudonymous accounts who can be targeted by state or other actors," the company said.

It recommended users seeking to keep their identities veiled not add a publicly known phone number or email address to their Twitter account.

"If you operate a pseudonymous Twitter account, we understand the risks an incident like this can introduce and deeply regret that this happened," it said.

The revelation of the breach comes while Twitter is in a legal battle with Tesla CEO Elon Musk over his attempt to back out from his previous offer to buy San Francisco-based Twitter for US$44 billion.

CTVNews.ca Top Stories

Days after a political sign was erected outside Lululemon founder Chip Wilson's Vancouver mansion, the waterfront property has been vandalized with graffiti.

A disgraced Winnipeg high school football coach convicted of sexual assault and luring will spend 20 years behind bars.

Two people are in hospital after they were chased and shot at in what appears to be an act of road rage before eventually flipping their car while trying to escape, police say.

Toronto Coun. Michael Thompson 'forced himself on' a woman who awoke to find him standing over her after she fell asleep drunk, the Crown alleged Monday, as the five-day sexual assault trial of the six-term politician began in Bracebridge, Ont.

Local Spotlight

Videos of a meteor streaking across the skies of southern Ontario have surfaced and small bits of the outer space rock may have made it to land, one astronomy professor says.

A unique form of clouds made an appearance over the skies of Ottawa on Sunday evening.

Bernie Hicks, known as the ‘Batman of Amherst,’ always wanted to sit in a Batmobile until a kind stranger made it happen.

Bubi’s Awesome Eats, located on University Ave West took to social media to announce the closure on Friday.

Weeneebayko Area Health Authority and the Government of Ontario have awarded a $1.8 billion fixed-price contract to design, build and finance a new Far North hospital.

Manitobans are in cleanup mode after intense winds barreled through southern parts of the province this weekend.

Avry Wortman, 13, scored two touchdowns on Sunday during her team's win in the under 14 Greater Moncton Football Association.

A gargantuan gourd – affectionately named ‘Orangina’ by the urban gardeners who grew it in the front yard of their Vancouver home – earned the massive honour of being named B.C.’s heaviest giant pumpkin Saturday.

Chantal Kreviazuk is set to return to Winnipeg to mark a major milestone in her illustrious musical career.