Are 32 million Twitter passwords being sold on the dark web?
Social media giant 'confident' its systems have not been hacked after website reports data breach
Millions of Twitter passwords have reportedly surfaced online and are being sold on the dark web.
LeakedSource, which collects credentials from data breaches, says it has received more than 32 million records, including email addresses, usernames and passwords.
"We have very strong evidence that Twitter was not hacked, rather the consumer was," it says.
Subscribe to The Week
Escape your echo chamber. Get the facts behind the news, plus analysis from multiple perspectives.
Sign up for The Week's Free Newsletters
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
A spokesperson for the social media giant said it was "confident" its systems had not been breached.
LeakedSource believes that malware was responsible for the breach and sent usernames and passwords saved in browsers such as Chrome and Firefox to the hackers.
A Russian, known by his alias Tessa88, is selling the credentials for 10 bitcoins, or about £4,000, according to Zdnet.
The most commonly used passwords in the data cache included "123456", "qwerty" and "password".
These are not good passwords, says Mashable. "An analogy to using these would be locking your front door, but then leaving keys on your porch. And breaking the lock. And punching a big hole in the door."
However, nearly 150,000 of the passwords contained more than 30 characters, which means that the strength of a password "is irrelevant" if the user has been infected with the malware, says LeakedSource. Turning on two-factor authentication will help keep an account more secure.
Based on the emails provided, many of the affected users appear to be from Russia. The site says it has verified the authenticity of the passwords with 15 users, all of whom confirmed they were genuine.
But some experts have expressed scepticism about the authenticity of the data, Tech Crunch reports.
"They may well be old leaks if they're consistent with the other big ones we've seen and simply haven't seen the light of day yet," said Troy Hunt, the creator of a site called haveibeenpwned.com, which catalogues breaches.
Sign up for Today's Best Articles in your inbox
A free daily email with the biggest news stories of the day – and the best features from TheWeek.com
-
Today's political cartoons - February 1, 2025
Cartoons Saturday's cartoons - broken eggs, contagious lies, and more
By The Week US Published
-
5 humorously unhealthy cartoons about RFK Jr.
Cartoons Artists take on medical innovation, disease spreading, and more
By The Week US Published
-
Brodet (fish stew) recipe
The Week Recommends This hearty dish is best accompanied by a bowl of polenta
By The Week UK Published
-
Who is the Hat Man? 'Shadow people' and sleep paralysis
In Depth 'Sleep demons' have plagued our dreams throughout the centuries, but the explanation could be medical
By The Week Staff Published
-
Why Assad fell so fast
The Explainer The newly liberated Syria is in an incredibly precarious position, but it's too soon to succumb to defeatist gloom
By The Week UK Published
-
Romania's election rerun
The Explainer Shock result of presidential election has been annulled following allegations of Russian interference
By Sorcha Bradley, The Week UK Published
-
Russia's shadow war in Europe
Talking Point Steering clear of open conflict, Moscow is slowly ratcheting up the pressure on Nato rivals to see what it can get away with.
By The Week UK Published
-
Cutting cables: the war being waged under the sea
In the Spotlight Two undersea cables were cut in the Baltic sea, sparking concern for the global network
By The Week UK Published
-
The nuclear threat: is Vladimir Putin bluffing?
Talking Point Kremlin's newest ballistic missile has some worried for Nato nations
By The Week UK Published
-
Russia vows retaliation for Ukrainian missile strikes
Speed Read Ukraine's forces have been using U.S.-supplied, long-range ATCMS missiles to hit Russia
By Arion McNicoll, The Week UK Published
-
Has the Taliban banned women from speaking?
Today's Big Question 'Rambling' message about 'bizarre' restriction joins series of recent decrees that amount to silencing of Afghanistan's women
By Harriet Marsden, The Week UK Published