7 comments

[ 3.5 ms ] story [ 31.0 ms ] thread
https://infosec.exchange/@briankrebs/109569533436686804

BrianKrebs @briankrebs@infosec.exchange

A user on the cybercrime forum Breached is selling what they claim is info scraped via Twitter APIs from 400 million Twitter profiles, including email, name, account name, follower count and in many cases phone number. This was first brought to my attention by Alon Gal at Hudson Rock.

https://www.linkedin.com/in/alon-gal-utb/

The seller told me they scraped the data using the same set of weaknesses in Birdsite APIs that allowed the scraping (and publishing) early this year of profile data on 5.4M Twitter users.

https://www.bleepingcomputer.com/news/security/54-million-tw...

They said they scraped the data via an exploit that was patched earlier this year, in the login api, and specifically the part of it that checks for duplicate accounts.

That, according to the seller, leaked the Twitter user ID, which was then converted via another Twitter API into a username. They also said that same iterative process worked for user telephone numbers.

The vulnerability that was reportedly used to scrape the previously dumped 5.4M twitter user data set was reported to Hacker One on Jan. 1, 2022.

https://hackerone.com/reports/1439026

The seller released 1,000 new records as a teaser, and is trying to get Twitter to buy the data for an undisclosed amount.

They also pasted a number of "celebrity" accounts directly into the sales thread. Curiously, this record set does not have the phone number associated w/ my Twitter account. But it was in the 5.4M scrape that got released on the same forum last month. However, I removed the burner phone number from my profile around the time the seller said they scraped this data (beginning of 2022).

The data in both the teaser and the 1,000 user file includes follower counts for each user, and a spot check on about a half dozen of them show follower numbers consistent with what Archive.org and Sociable says about follower accounts at the beginning of Jan 2022/end of December.

They are selling it through the escrow service set up by the administrators of the forum, which is what you'd expect to see in a real offering for this volume of data.

https://twitter.com/iamraisini/status/1606785472512016384

RΛISINI ライシニ @iamraisini

Big Data Breach, Big Names, Bigger Damage. “The threat actor provided a valid sample of 1,000 notable accounts and included the private information of @AOC, @briankrebs, @VitalikButerin, @kevinolearytv, Trump Jr., and many more,” Gal wrote in his LinkedIn post @elonmusk

They claim data was obtained up to early 2022 due to an exploit in Twitter & in their post they talk directly to Elon asking him to buy the data to avoid GDPR lawsuits. In an independent verification the data appears to be legitimate, follow for updates!

https://breached.vc/Thread-Selling-Twitter-Data-Breach-400-m...

>buy the data to avoid GDPR lawsuits

You cant "buy the data", but what you can buy is couple of south American assassins.

Just FYI, this person has posted many dubious claims about Musk. I’m no Musk fan but this person appears to mix fact and fiction.

1) claims to have overheard Musk having a conversation with Qataris at the world cup

2) claims to have Tesla shares worth a billion

So who wants to chip in and buy it? ;)
I no longer am seeing any "why isn't anyone talking about this" binance spam in the replies of crypto accounts tweets. It suddenly all stopped. i wonder if this had anything to do with this. It's likely there was some exploit that allowed the hackers to access logins or sessions of thousands of accounts to post binance spam, which got patched under Musk's leadership.

indeed

https://twitter.com/WallStreetSilv/status/160205661916405760...

The typing style definitively seems like an American user applying the bare minimum red herring stylometrics to appear as someone with another mother tongue. Considering the timing I wouldn't be at all surprised to find out that this leak is from a recently departed employee. They likely have the full set but are only selling data from a certain point in time.