A hacker claims to be selling public and private data of 400 million Twitter users, which was collected in 2021 using an API vulnerability that has now been patched. The amount he is asking for the exclusive sale is $200,000.
See also: DuckDuckGo: Block Google sign-in pop-ups on all sites

On the hacking forum “Breached,” which is often used to sell user data obtained through breaches, a threat actor named “Ryushi” is reportedly selling the allegedly stolen data. The threat actor claimed to have harvested the data of 400 million unique Twitter users using a vulnerability. The hackers warned Elon Musk and Twitter that if they did not buy the data soon, it could lead to a hefty fine due to the European GDPR privacy law. Ryushi said in a forum post addressed to Elon Musk and Twitter: “Purchasing this data outright is your best option if you want to avoid paying $276 million in GDPR violation fines , like Facebook did (for scraping 533 million users).” In his post, Ryushi included a link to another post that describes how other “hackers” could use this information for BEC attacks , crypto-scams, and phishing . The post also includes sample data for 37 celebrities, politicians, journalists, businesses, and government organizations. These individuals include Alexandria Ocasio-Cortez, Donald Trump Jr., Mark Cuba, Kevin O’Leary, and Piers Morgan. See also: Top sports betting company BetMGM hacked

The user profiles show email addresses, names, usernames, number of followers, account creation date, and other public and private Twitter data.
While it appears that all of the exposed profiles have email addresses, many of them do not have a phone number listed.
While almost all of this information is publicly available to every Twitter user, phone numbers and email addresses are considered private information.
Ryushi told BleepingComputer that he is trying to sell the data exclusively to Twitter itself for $200,000 and then delete the stolen data. However, if an exclusive purchase does not occur, they will sell copies for $60,000 each to multiple buyers.
When asked if they have contacted Twitter to demand a ransom, they admitted that they did so but have not received any response.
The data was collected using an API vulnerability that has now been fixed
The threat actor confirmed to BleepingComputer that it collected the private phone numbers and email addresses using an API vulnerability that Twitter patched in January 2022 and had previously been linked to the data breach of 5.4 million users.
While Twitter patched the vulnerability in January 2022, it has now been confirmed that it was used by multiple hackers who managed to steal various data from Twitter users.
See also: Vice Society ransomware: Adopted a new custom encryptor

This leak came at a most inopportune time for Twitter.
The Irish Data Protection Commission (DPC), an EU privacy watchdog, has launched an investigation into the 5.4 million user records stolen in 2021 using this vulnerability.
Although Twitter patched the vulnerability in January, it was subsequently found that several threat actors used it to harvest various user data.
However, according to Alon Gal of Hudson Rock, he “independently” confirmed that the leaked samples appear to be authentic.
Note that, at this time, it is not possible to confirm that there are 400 million users in the database, as Hudson Rock notes in a tweet.
Another threat actor claimed to have used this vulnerability to scrape the data of 17 million users. However, this leak is still private and not for sale.
For any updates regarding this attack on Twitter and its new CEO, Elon Musk, we will keep you updated.
Source: bleepingcomputer.com
