User's Secret Account have been Figured Out by the Hackers
A security vulnerability on Twitter had allowed a bad actor to search out the account names related to certain email addresses and phone numbers as confirmed by Twitter on Friday. Twitter had initially patched the difficulty in January once it had received a report through its bug bounty program, however a hacker had managed to exploit the flaw before Twitter would even had any idea regarding it.
HIGHLIGHTS
- Twitter allows users to find accounts names with their email id and phone number
- Hackers managed to exploit the flaw before Twitter had any knowledge about this
- The hacker amassed database of 5.4 million accounts, sell it for $30,000
Also Read: How hackers access your iPhone without your knowledge?
The vulnerability, that had stemmed from an update the platform had made to its code in June month of 2021, which got overlooked until earlier this year. This gave hackers many months to exploit the flaw, though Twitter had mentioned that it “had no proof to recommend somebody had taken advantage of the vulnerability” at the time of its discovery.
As per last month's report, suggested otherwise and revealed that a hacker had managed to exploit the vulnerability while it would flew under Twitter’s rader. The hacker had reportedly amassed a database of 5.4 million accounts by providing an advantage of the flaw, then tried to sell the information on a hacker forum for $30,000. After the data has been analyzed which was posted to the forum, Twitter confirmed that its user information had been compromised.
Well, it has been still unclear about the number of users who have truly been affected although, and Twitter doesn’t appear to know about this, either. While Twitter has mentioned that it has planned on notifying affected users, it was not “able to verify each account that was probably impacted.” Twitter advises that anyone concerned about their secret accounts should enable two-factor authentication, along with this they should attach an email address or phone number that would not be known publicly to the account they do not wish to get associated with.
Also Read: Twitter is all set to raise the Blue Subscription Price