[su_heading size=”18″ margin=”40″]An anonymous hacker is selling over 32 million cleartext Twitter passwords on the Dark Web for 10 Bitcoins (~$5800). Twitter has yet to make any official statement on the matter.[/su_heading]
LeakedSource, the company that has the data in its hands thanks to a "benefactor", reports that there are 32,888,300 records in the leaked database, not 380 million, as the hacker claims.
The company adds that the data includes entries with a recent timestamp, but it does not actually believe that Twitter was hacked.
The data likely came from a keylogger or password dumper.
Judging by the way the records are stored, LeakedSource believes that the source of this leak is some sophisticated malware capable of stealing passwords from browsers, or capable of recording keystrokes via a keylogger.
Its researchers came to this conclusion after analyzing entries that instead of a password had values such as “null” or “<blank> "
These are the standard formats used in browsers like Chrome and Firefox, when users have set the browser to save and remember their passwords, but during a login attempt, they press Enter without entering a password, creating a blank entry.
[su_heading size=”18″ margin=”40″]Russian users in the spotlight[/su_heading]
LeakedSource also reports that most of the email domains are from Russian services, leading it to believe that this data is the result of a malware campaign that primarily targeted Russian users.
Over the weekend, Mark Zuckerberg's Twitter and Pinterest accounts were hacked. LeakedSource adds that this incident was unrelated to the recent data leak as his name was not included in the file.
This is not the first time that a leak of this magnitude has occurred, as previous incidents involved the sale of data stolen from various networks such as MySpace (427,484,128 records), LinkedIn (167,370,940 records), Tumblr (65,469,298 records) and VK.com (100,544,934 records).
Below is the list of the 25 most popular passwords according to LeakedSource.



