Skip to main content

Oh great, now our Twitter data is for sale on the dark web

In case you haven’t been closely following in-depth hacker news feeds (and we don’t blame you if you haven’t), you may have missed an announcement in January from HackerOne detailing a security vulnerability in the Twitter code. The vulnerability let hackers steal phone numbers and emails of users.

Well, a list of millions of Twitter users just showed up for sale on the dark web.

Recommended Videos

Restore Privacy, a security and privacy watchdog, reported the list of 5.4 million Twitter user emails and phone numbers for sale on a dark web site called Breached Forums. The hacker selling the list claims it contains the private data of “Celebrities, to Companies, randoms, OGs, etc.”

Please enable Javascript to view this content

The vulnerability found in January and the sale of personal datasets from Twitter are too closely linked to be mere coincidence.

In January, HackerOne user zhirinovskiy submitted a bug report he had found while analyzing Twitter’s codebase. It was an exploit that could potentially allow a threat actor to access the emails and phone numbers of Twitter users. Although there was no sign of a data breach at the time, zhirinovskiy was concerned.

“This is a serious threat,” zhirinovskiy said in his bug report. “As people can not only find users who have restricted the ability to be found by email/phone number, but any attacker with a basic knowledge of scripting/coding can enumerate a big chunk of the Twitter user base unavailable to enumeration prior (create a database with phone/email to username connections).”

“Thank you for your report @zhirinovksiy,” a Twitter employee named bugtriage_simon replied to the report. “We’re looking into this and will keep you updated when we have additional information. Thank you for thinking of Twitter security.”

The reply came on January 6, five days after zhirinovskiy posted his report.

On January 13, Twitter closed the report and commented: “We consider this issue to be fixed now. Can you please confirm?”

“I can confirm the issue is fixed,” zhirinovskiy replied the same day. Twitter rewarded him for his efforts.

Judging from the exchange of comments on the initial bug report, it took nearly two weeks for Twitter to fix the vulnerability. At some point, a threat actor snuck in and stole 5.4 million datasets. Whether it was done before zhirinovskiy discovered the exploit or after he had posted it remains unknown. What is known is those emails and phone numbers are now for sale.

If your data was included in the breach, you can expect to receive an uptick in spam emails and scammer calls. We recommend using Apple’s Hide My Email if you have iPhone. Also, check out our tips for increasing your online privacy.

Nathan Drescher
Former Digital Trends Contributor
Nathan Drescher is a freelance journalist and writer from Ottawa, Canada. He's been writing about technology from around the…
This 17-inch HP Laptop is $280 off at Best Buy — just a few hours left
The HP 17.3-inch Laptop with Microsoft Excel on the screen.

If you're looking for laptop deals, Best Buy is an excellent source of huge discounts. Check out this offer for the HP 17.3-inch Laptop: a incredibly low price of $350, for savings of $280 on its original price of $630. That's a steal any way you look at it, but you're going to have to hurry if you want to take advantage of this bargain because it's only available today. There are just a few hours remaining before the laptop's price returns to normal, so if you don't want to miss out, you're going to have to make your purchase right now.

Why you should buy the HP 17.3-inch Laptop
The HP 17.3-inch Laptop is a fantastic device for working professionals and students alike, as it provides reliable performance with the AMD Ryzen 5 7430U processor and AMD Radeon graphics, alongside 8GB of RAM. With these specifications, it's not going to challenge the best laptops, but it will be more than enough for daily tasks like online research and report writing, as well as recreational activities such as catching up on social media. The HP 17.3-inch Laptop also comes with Windows 11 Home in S Mode pre-installed in its 512GB SSD, which will give you enough space for all of your important files.

Read more
Apple may finally fix the worst things about the MacBook Pro
Someone using a MacBook Pro M4.

Future MacBook Pro models may trade in Apple’s now signature notch design for a hole-punch camera motif.

A component road map from research firm Omdia details that Apple has plans to make changes to the display of its 14-inch and 16-inch MacBook Pro models that will be released in 2026.

Read more
What is AppleCare+ and is it worth adding to your MacBook?
A person using a MacBook with an Apple Studio Display.

If you’ve just kitted yourself out with one of the best Macs, you might be looking to protect your purchase with some kind of insurance. If that’s the case, you’ve probably heard of AppleCare+. But what exactly is AppleCare+, and should you buy it for your MacBook?

Here, you’ll find everything you need to know about AppleCare+, including what it is, how much it costs, and whether it’s worth it. Read on and you’ll be able to make an informed decision for your Mac in just a few minutes.
What is AppleCare+?

Read more