AP

Twitter leak exposes 235 million email addresses from hack

Jan 6, 2023, 11:40 AM | Updated: 11:58 am

Personal emails linked to 235 million Twitter accounts hacked some time ago have been exposed according to Israeli security researcher Alon Gal — making millions vulnerable to having their accounts compromised or identities exposed if they have used the site anonymously to criticize oppressive governments, for instance.

Gal, who is the co-founder and chief technology officer at cybersecurity firm Hudson Rock, wrote in a LinkedIn post this week that the leak “will unfortunately lead to a lot of hacking, targeted phishing, and doxxing.”

While account passwords were not leaked, malicious hackers could use the email addresses to try to reset people’s passwords, or guess them if they are commonly used or reused with other accounts. That’s especially a risk if if the accounts are not protected by two-factor authentication, which adds a second layer of security to password-protected accounts by having users enter an auto-generated code to log in.

People who use Twitter anonymously should have a Twitter-dedicated email address that does not disclose who they are and is used solely for Twitter, experts say.

Though the hack appears to have taken place before Elon Musk took over Twitter, the news of the leaked emails adds another headache for the billionaire, whose first couple months as head of Twitter have been chaotic, to say the least.

Twitter did not immediately respond to a message for comment on the hack.

News of the breach could put the company in trouble with the Federal Trade Commission. The San Francisco company signed a consent agreement with the agency in 2011 that required it to address serious data-security lapses.

Twitter paid a $150 million penalty last May, several months before Musk’s takeover, for violating the consent order. An updated version established new procedures requiring the company to implement an enhanced privacy-protection program as well as beefing up information security.

In November, a group of Democratic lawmakers asked federal regulators to investigate any possible violations by the platform of consumer-protection laws or of its data-security commitments.

The FTC said at the time it is “tracking recent developments at Twitter with deep concern,” though no formal investigation has been announced. But experts and current and former Twitter employees have been warning of serious security risks flowing from the drastically reduced staff and deepening disorder within the company.

In August, Twitter’s former head of security filed a whistleblower complaint alleging that the company misled regulators about its poor cybersecurity defenses and its negligence in attempting to root out fake accounts that spread disinformation.

Among Peiter Zatko’s most serious accusations is that Twitter violated the terms of the 2011 FTC settlement by falsely claiming that it had put stronger measures in place to protect the security and privacy of its users.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

Lead water pipes pulled from underneath the street are seen in Newark, N.J., Oct. 21, 2021. (AP Pho...

Associated Press

Biden to require cities to replace harmful lead pipes within 10 years

The Biden administration has previously said it wants all of the nation's roughly 9 million lead pipes to be removed, and rapidly.

3 days ago

Facebook's Meta logo sign is seen at the company headquarters in Menlo Park, Calif., on, Oct. 28, 2...

Associated Press

Meta shuts down thousands of fake Facebook accounts that were primed to polarize voters ahead of 2024

Meta said it removed 4789 Facebook accounts in China that targeted the United States before next year’s election.

3 days ago

A demonstrator in Tel Aviv holds a sign calling for a cease-fire in the Hamas-Israel war on Nov. 21...

Associated Press

Hamas releases a third group of hostages as part of truce, and says it will seek to extend the deal

The fragile cease-fire between Israel and Hamas was back on track Sunday as the first American was released under a four-day truce.

8 days ago

Men look over the site of a deadly explosion at Al-Ahli Hospital in Gaza City, Wednesday, Oct. 18, ...

Associated Press

New AP analysis of last month’s deadly Gaza hospital explosion rules out widely cited video

The Associated Press is publishing an updated visual analysis of the deadly Oct. 17 explosion at Gaza's Al-Ahli Hospital.

11 days ago

Peggy Simpson holds a photograph of law enforcement carrying Lee Harvey Oswald's gun through a hall...

Associated Press

JFK assassination remembered 60 years later by surviving witnesses to history, including AP reporter

Peggy Simpson is among the last surviving witnesses who are sharing their stories as the nation marks the 60th anniversary.

11 days ago

Israeli Prime Minister Benjamin Netanyahu, chairs the weekly cabinet meeting in Jerusalem, Sunday, ...

Associated Press

Israeli Cabinet approves cease-fire with Hamas; deal includes release of 50 hostages

Israel’s Cabinet on Wednesday approved a cease-fire deal with the Hamas militant group that would bring a temporary halt to a devastating war.

12 days ago

Sponsored Articles

Follow @KTAR923...

The best ways to honor our heroes on Veterans Day and give back to the community

Veterans Day is fast approaching and there's no better way to support our veterans than to donate to the Military Assistance Mission.

...

Dierdre Woodruff

Interest rates may have peaked. Should you buy a CD, high-yield savings account, or a fixed annuity?

Interest rates are the highest they’ve been in decades, and it looks like the Fed has paused hikes. This may be the best time to lock in rates for long-term, low-risk financial products like fixed annuities.

...

DAY & NIGHT AIR CONDITIONING, HEATING AND PLUMBING

Importance of AC maintenance after Arizona’s excruciating heat wave

An air conditioning unit in Phoenix is vital to living a comfortable life inside, away from triple-digit heat.

Twitter leak exposes 235 million email addresses from hack