Twitter freezes accounts in the wake of password leak

Company requests password resets as security measure

Twitter has been freezing accounts and issuing password reset emails in the wake of a data leak that saw over 32 million passwords exposed.

The company's position was explained in an official blog post by Twitter's trust and information security officer Michael Coates, who maintained that the credentials were "not obtained from a hack of Twitter's servers".

Advertisement - Article continues below

"The purported Twitter @names and passwords may have been amassed from combining information from other recent breaches, malware on victim machines that are stealing passwords for all sites, or a combination of both," he said. "Regardless of origin, we're acting swiftly to protect your Twitter account."

As the company stated in its initial response to the news, it has cross-checked the leaked data from recent breaches on MySpaceLinkedIn and Tumblr, as well as the information discovered yesterday.

"As a result," Coates wrote, "a number of Twitter accounts were identified for extra protection. Accounts with direct password exposure were locked and require a password reset by the account owner."

"Your account won't be accessible until you do so," he warned, "to ensure that unauthorized individuals don't have access." Coates also reiterated the boilerplate security advice given by experts in these situations: use a strong password, enable two-factor authentication, and use a password manager.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

09/06/2016: 32 million Twitter passwords go for sale on the dark web, but Twitter 'not hacked'

Twitter has denied that its systems were breached by hackers, after more than 32 million users' passwords were found for sale on the dark web.

The news comes after a rash of data breaches from sites such as MySpace, LinkedIn and Tumblr, all of which have had user credential databases leaked online by hackers.

However, while these companies were the victims of cyberattacks, Twitter was quick to stress that the company's systems "have not been breached".

"We are confident that these usernames and credentials were not obtained by a Twitter data breach," a spokesman told IT Pro.

"In fact, we've been working to help keep accounts protected by checking our data against what's been shared from recent other password leaks."

Multiple security experts have agreed with this diagnosis, after Reddit was forced to issue reset password emails to 100,000 users because of credentials leaked in the LinkedIn hack, while Netflix and Facebook took similar action.

Advertisement - Article continues below

"The person that is selling the Twitter credentials has been behind many other similar credential leaks before," F-Secure chief research officer Mikko Hypponen told IT Pro. "So, we believe the database she is selling now is real."

The data was provided by an individual known as 'Tessa88' to database search tool LeakedSource, which wrote in a blog post that "out of 15 users we asked, all 15 verified their passwords". Many of the affected emails are Russian.

While the database is real, security experts IT Pro spoke with agreed that it is not the result of a hack. "We do not believe it's stolen from Twitter," Hypponen said, "but from users' own systems with keyloggers."

His views have been echoed by both LeakedSource and infosec analyst Graham Cluley. 

Cluley confirmed that in the wake of this latest data leak, his advice for users is the same as it is after every breach, telling IT Pro: "If you're concerned your password may have been compromised, you should change it."

Advertisement - Article continues below

"Furthermore, you should change your passwords if you are using the same password anywhere else on the net - a sadly all too common problem," he warned.

"Finally, folks should enable two-step verification on their Twitter account - which should make it hard for accounts to be hijacked even if hackers have grabbed your password."

Featured Resources

The case for a marketing content hub

Transform your digital marketing to deliver customer expectations

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

IT faces new security challenges in the wake of COVID-19

Beat the crisis by learning how to secure your network

Download now
Advertisement
Advertisement

Recommended

Visit/marketing-comms/social-media/355824/trumps-leaked-executive-order-targets-social-media-companies
social media

Trump’s leaked executive order targets social media companies

28 May 2020
Visit/security/encryption/355820/k2view-innovates-in-data-management-with-new-encryption-patent
encryption

K2View innovates in data management with new encryption patent

28 May 2020
Visit/security/phishing/355810/zloader-malware-returns-as-a-coronavirus-phishing-scam
phishing

ZLoader malware returns as a coronavirus phishing scam

27 May 2020
Visit/security/hacking/355806/anarchygrabber-hack-steals-discord-tokens-ids-and-passwords
hacking

AnarchyGrabber hack steals Discord tokens, IDs and passwords

27 May 2020

Most Popular

Visit/infrastructure/server-storage/355785/dell-emc-poweredge-r7525-review-an-epyc-core-density-to-make
Server & storage

Dell EMC PowerEdge R7525 review: An EPYC core density to make Intel weep

26 May 2020
Visit/infrastructure/network-internet/355792/intel-releases-wi-fi-and-bluetooth-driver-updates-for
Network & Internet

Intel releases Wi-Fi and Bluetooth driver updates for Windows 10

26 May 2020
Visit/operating-systems/microsoft-windows/355781/microsoft-confirms-further-issues-with-troublesome
Microsoft Windows

Microsoft's latest Windows 10 update is causing yet more issues

26 May 2020