Hackers sold 400 million Twitter user data and shouted to Musk: do you want to "spend money to save the disaster" or face huge EU fines?
CTOnews.com, Dec. 27 (Xinhua)-- A hacker is asking $200000 (about 1.394 million yuan) on the Dark Internet to sell 400 million Twitter user data that exploited a loophole (now fixed) in 2021. Hackers named "Ryushi" sold data dumps (data dump) on the Breached hacker forum, which is often used to sell user data stolen by various security incidents.
Hackers named "Ryushi" said in the post that they used the vulnerability to successfully collect data from more than 400 million Twitter users. And the hackers said in the post that Elon Musk (Elon Musk) should buy the data if he wants to avoid huge fines under European GDPR regulations.
"if Twitter or Elon Musk reads this post, can you consider buying the data or facing a fine of more than 5.4 million euros for the breach of data from more than 400 million users?" Ryushi wrote in the post.
The post also mentioned Facebook, which was fined $276 million by the European Union for the theft and disclosure of 533 million user data.
CTOnews.com learned that the threat actor also linked to a post explaining how the data was abused by other threat actors for phishing attacks, cryptocurrency fraud and BEC attacks.
The post also shared sample data from 37 celebrities, journalists, companies and institutions, including Alexandria Ocasio-Cortez, Donald Trump JR, Mark Cuba, Kevin O'Leary and Piers Morgan. In addition, a larger sample of 1000 Twitter user profiles was later leaked.
These user profiles contain public and private Twitter data, including the user's email address, name, user name, number of followers, creation date and phone number. Although all leaked materials seem to have e-mail addresses associated with them, many of them do not have phone numbers.