Twitter Denies Site Hack in Reputed Account Credential Dump

Écrit par
Brian Prince
Brian Prince
Published: May 9, 2012
Updated: Feb 2, 2021
2 minute read
eWeek Le contenu et les recommandations de produits sont indépendants de la rédaction. Nous pouvons gagner de l'argent lorsque vous cliquez sur des liens vers nos partenaires. En savoir plus

Twitter denied on May 9 that it was hacked in response to reports that thousands of passwords and user names had been stolen and posted online.

The statement comes in response to reports that some 58,978 user name and password combinations belonging to Twitter users were dumped online Monday in a series of postings to Pastebin. According to Twitter, thousands of the user names and passwords are duplicates, and many others do not belong to legitimate accounts.

€œWe’ve looked into this and can confirm that Twitter was not compromised,€ Twitter spokesperson Carolyn Penner told eWEEK in an email. €œFor extra precaution, yesterday, we pushed out password resets to accounts that may have been affected. For those who are concerned that their account may have been compromised, we suggest resetting your passwords and more in our Help Center.€

€œIt’s worth noting that, so far, we’ve discovered that the list of alleged accounts and passwords found on Pastebin consists of more than 20,000 duplicates, many spam accounts that have already been suspended and many log-in credentials that do not appear to be linked (that is, the password and user name are not actually associated with each other),€ she added.

Penner would not say how many passwords were reset.

Michael Sutton, vice president of security research at Zscaler€™s ThreatLabZ, noted that social networking credentials can become €œvaluable currency€ in the cyber-underground and are often targeted by botnets and phishing campaigns.

€œSocial networking credentials are valuable because networks, such as Facebook and Twitter, represent trusted means of communication,€ he said. €œUnlike spam email, which is completely untrusted and could come from any source, messages from contacts that you’ve explicitly permitted into your personal network are considered trusted, and therefore links sent in such messages have a far higher click-through rate. This fact has not been lost on criminals who go to great lengths to harvest or purchase social networking credentials and then leverage the compromised accounts to social engineer victims into visiting malicious sites.”

Kapil Raina, director of product marketing at Zscaler, noted that a compromised Twitter account could potentially be leveraged in other attacks.

Advertisement

€œA compromised Twitter account lends itself well to being able to do this sort of targeted Trojan broadcasting,€ he said. €œUsing short URLs, users are more apt to click on malicious links and get infected as they assume a tweet from a €˜trusted€™ source is legitimate. The ultimate goal generally is to use the compromised account as the beachhead for a more lucrative attack inside an organization.€

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Propriété de TechnologyAdvice. © 2026 TechnologyAdvice. Tous droits réservés

Divulgation publicitaire : Certains des produits qui apparaissent sur ce site proviennent d'entreprises dont TechnologyAdvice reçoit une compensation. Cette compensation peut influencer la façon dont les produits apparaissent sur ce site, notamment l'ordre dans lequel ils apparaissent. TechnologyAdvice n'inclut pas toutes les entreprises ou tous les types de produits disponibles sur le marché.