Categories
Audio Sources - Full Text Articles

Data from 5.4M Twitter users obtained from multiple threat actors and combined with data from other breaches

Listen to this article

The massive data breach suffered by Twitter that exposed emails and phone numbers of its customers may have impacted more than five million users.

At the end of July, a threat actorĀ leaked data of 5.4 million Twitter accountsĀ that were obtained by exploiting a now-fixed vulnerability in the popular social media platform.

The threat actor offered for sale the stolen data on the popular hacking forum Breached Forums. In January, a report published on Hacker claimed the discovery of a vulnerability that can be exploited by an attacker to find a Twitter account by the associated phone number/email, even if the user has opted to prevent this in the privacy options.

ā€œThe vulnerability allows any party without any authentication to obtain aĀ twitter ID(which is almost equal to getting the username of an account) ofĀ anyĀ user by submitting a phone number/email even though the user hasĀ prohibitted this action in the privacy settings. The bug exists due to the proccess of authorization used in the Android Client of Twitter, specifically in the procces of checking the duplication of a Twitter account.ā€Ā ā€ reads theĀ descriptionĀ in the report submitted byĀ zhirinovskiyĀ via bug bounty platform HackerOne.Ā ā€œThis is a serious threat, as people can not only find users who have restricted the ability to be found by email/phone number, but any attacker with a basic knowledge of scripting/coding can enumerate a big chunk of the Twitter user base unavaliable to enumeration prior (create a database with phone/email to username connections). Such bases can be sold to malicious parties for advertising purposes, or for the purposes of tageting celebrities in different malicious activitiesā€

The seller claimed that the database was containing data (i.e. emails, phone numbers) of users ranging from celebrities to companies. The seller also shared a sample of data in the form of a csv file.

In August, Twitter confirmed that the data breach was caused by theĀ now-patched zero-day flaw submitted by the researchersĀ zhirinovskiyĀ via bug bounty platform HackerOne and that he received a $5,040 bounty.

ā€œWe want to let you know about a vulnerability that allowed someone to enter a phone number or email address into the log-in flow in the attempt to learn if that information was tied to an existing Twitter account, and if so, which specific account.ā€Ā reads the Twitter’s advisory. ā€œIn January 2022, we received a report through our bug bounty program of a vulnerability that allowed someone to identify the email or phone number associated with an account or, if they knew a person’s email or phone number, they could identify their Twitter account, if one existed,ā€ continues the social media firm.

ā€œThis bug resulted from an update to our code in June 2021. When we learned about this, we immediately investigated and fixed it. At that time, we had no evidence to suggest someone had taken advantage of the vulnerability.ā€

This week, the website 9to5mac.com claimed that the data breach was word than initially reported by the company. The website reports that multiple threat actors exploited the same flaw and the data available in the cyberscrime underground have differed sources.

ā€œA massiveĀ TwitterĀ data breach last year, exposingĀ more than five million phone numbers and email addresses, was worse than initially reported. We’ve been shown evidence that the sameĀ securityĀ vulnerability was exploited by multiple bad actors, and the hacked data has been offered for sale on the dark web by several sources.ā€ reads the post published by 9to5mac.com

9to5Macā€˜s claims are based on the availability of the dataset that contained the same information in a different format offered by a a different threat actor. The source told the website that the database was ā€œjust one of a number of files they have seen.ā€ It seems that the impacted accounts are only those having the ā€œDiscoverability | Phone option (which is hard to find within Twitter’s settings)ā€ enabled in late 2021.

The archive seen by 9to5Mac includes data belonging to Twitter users in the UK, almost every EU country, and parts of the US.

ā€œI have obtained multiple files, one per phone number country code, containing the phone number <-> Twitter account name pairing for entire country’s telephone number space from +XX 0000 to +XX 9999.ā€ the source told 9to5Mac. ā€œAny twitter account which had the Discoverability | Phone option enabled in late 2021 was listed in the dataset.ā€

The experts speculate that multiple threat actors had access to the Twitter database and combined it with data from other security breaches.

The security researcher behind the account @chadloder (Twitter after the disclosure of the news) told 9to5Mac that the ā€œemail-twitter pairings were derived by running existing large databases of 100M+ email addresses through this Twitter discoverability vulnerability.ā€

The researcher told the website that they would reach out to Twitter for comment, but the entire media relations team left the company.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

PierluigiĀ Paganini

(SecurityAffairs – hacking, Twitter)

The post Data from 5.4M Twitter users obtained from multiple threat actors and combined with data from other breaches appeared first on Security Affairs.