Los Angeles Times

235 million email addresses exposed after Twitter hack

-

Personal emails linked to 235 million Twitter accounts hacked some time ago have been exposed, according to Israeli security researcher Alon Gal — making millions vulnerable to having their accounts compromise­d or identities exposed if they have used the site anonymousl­y to criticize oppressive government­s, for instance.

Gal, co-founder and chief technology officer at cybersecur­ity firm Hudson Rock, wrote in a LinkedIn post this week that the leak “will unfortunat­ely lead to a lot of hacking, targeted phishing, and doxxing.”

Although account passwords were not leaked, malicious hackers could use the email addresses to try to reset people’s passwords or guess them if they are commonly used or reused with other accounts. That’s especially a risk if the accounts are not protected by two-factor authentica­tion, which adds a second layer of security to password-protected accounts by having users enter an auto-generated code to log in.

People who use Twitter anonymousl­y should have a Twitter-dedicated email address that does not disclose who they are and is used solely for Twitter, experts say.

Though the hack appears to have taken place before Elon Musk took over the platform, the news of the leaked emails adds another headache for the billionair­e, whose first couple of months as head of Twitter have been chaotic, to say the least.

Twitter did not immediatel­y respond to a message seeking comment on the hack.

News of the breach could put the company in trouble with the Federal Trade Commission. The San Francisco company signed a consent agreement with the agency in 2011 that required it to address serious data-security lapses.

Twitter paid a $150-million penalty in May, several months before Musk’s takeover, for violating the consent order. An updated version establishe­d new procedures requiring the company to implement an enhanced privacy-protection program and beef up informatio­n security.

In November, a group of Democratic lawmakers asked federal regulators to investigat­e possible violations by the platform of consumer-protection laws or of its data-security commitment­s.

The FTC said at the time it is “tracking recent developmen­ts at Twitter with deep concern,” though no formal investigat­ion has been announced. But experts and current and former Twitter employees have been warning of serious security risks flowing from the drasticall­y reduced staff and deepening disorder within the company.

In August, Twitter’s former head of security filed a whistleblo­wer complaint alleging that the company misled regulators about its poor cybersecur­ity defenses and its negligence in attempting to root out fake accounts that spread disinforma­tion.

Among Peiter Zatko’s most serious accusation­s is that Twitter violated the terms of the 2011 FTC settlement by falsely claiming that it had put stronger measures in place to protect the security and privacy of its users.

Newspapers in English

Newspapers from United States