Twitter Faces Probe After Data On 400m Users Offered For Sale

Ireland’s data protection office is to investigate an apparent security breach at Twitter after a hacker claimed to offer personal details from 400 million accounts for sale online.

The hacker, using the handle “Ryushi”, offered a sample of details from about 1,000 accounts on  23 December, the same day that Ireland’s Data Protection Commission (DPC) said it would investigate an earlier Twitter breach that affected about 5.4 million accounts.

Both incidents appear to have used the same data-scraping vulnerability, which Twitter said it fixed in January 2022.

Ryushi asked for $200,000 (£166,000) to hand over the data and delete it.

Data breach

The person suggested that it would be in Twitter’s best interests to buy the data itself “exclusively” in order to avoid a large data-protection fine.

The post referred to a 265m euro (£234m) fine the Ireland DPC levied on Facebook parent Meta in November over a data breach affecting about 533 million users.

Ireland’s DPC said it “will examine Twitter’s compliance with data-protection law in relation to that security issue”.

Twitter, which has no press office after it was cut by owner Elon Musk, has not commented on the latest supposed breach.

Celebrity accounts

The small sample of data released so far has included information from the accounts of US politician Alexandria Ocasio-Cortez and broadcaster Piers Morgan.

Computer security firm Hudson Rock, which first brought the latest breach to wider attention, said the hacker’s claim appears credible.

Hudson Rock chief technology officer Alon Gal told the BBC only 60 of the emails in the sampled data appeared in the data from the earlier incident, indicating that “this breach is different and significantly bigger”.

Gal noted that the hacker offered to use an escrow service to sell the data, which would release the funds only if certain conditions are met, another indication in favour of the breach being genuine.

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Anthropic Launches Enterprise-Focused Claude, Plus iPhone App

Two updates to Anthropic's AI chatbot Claude sees arrival of a new business-focused plan, as…

1 hour ago

TikTok Viewed As Chinese Influence Tool By Most Americans – Poll

Most people in the United States view TikTok as a Chinese influence tool a poll…

15 hours ago

Ofcom Confirms OnlyFans Investigation Over Age Verification

UK regulator confirms it is investigating whether OnlyFans is doing enough to prevent children accessing…

16 hours ago

Ex Google Staff Fired Over Israel Protest File NLRB Complaint

Dismissed staff file complaint with a US labor board, and allege Google unlawfully terminated their…

17 hours ago

Tesla Axes Entire Supercharger Team, Plus Senior Executives

Elon Musk dismisses two senior Tesla executives, plus the entire division that runs Tesla's Supercharger…

18 hours ago

Microsoft, OpenAI Sued By More Newspaper Publishers

Eight newspaper publishers in the US allege Microsoft and OpenAI used their millions of their…

20 hours ago