Twitter says hacking attack may have affected 250K users

Twitter logo
Best to tighten security measures

Twitter is the latest entity to undergo a security breach in the last few days, following large-scale attacks on the New York Times and Wall Street Journal.

"This week, we detected unusual access patterns that led to us identifying unauthorized access attempts to Twitter user data," wrote Bob Lord, director of information security, in a blog post. In all, 250,000 user accounts may have been affected by hackers.

Lord recounted how the company actually intercepted an attack as it was happening, shutting it down "in process" within moments.

"Our investigation has thus far indicated that the attackers may have had access to limited user information - usernames, email addresses, session tokens and encrypted/salted versions of passwords...," Lord continued.

Under fire

As a preventative measure, Twitter reset the passwords and revoked session tokens for potentially impacted accounts. Users whose accounts were compromised should receive an email alert from the company shortly if they have not received one already.

These users will need to change their passwords - "Your old password will not work when you try to log in to Twitter."

Twitter does not think that the breach was not the work of amateurs.

"[We] do not believe it was an isolated incident," Lord wrote. "The attackers were extremely sophisticated, and we believe other companies and organizations were similarly attacked.

"For that reason we felt that it was important to publicize this attack while we still gather information, and we are helping government and federal law enforcement in their effort to find and prosecute these attackers to make the internet safer for all users."

According to data released this week by GlobalWebIndex, Twitter reached 485 million members in 2012.

In addition to the Times and Journal, Lord also noted that Apple and Mozilla turned off Java by default in the companies' browsers following security concerns.

Lord too warned against Java in his post.

"We also echo the advisory from the U.S. Department of Homeland Security and security experts to encourage users to disable Java on their computers," he wrote.

A Twitter spokesperson would not disclose whether the attacks were isolated to the U.S. or had impacted other regions, citing security and privacy reasons.

While Twitter is taking action, Lord recommended users follow "good password hygiene" on Twitter and elsewhere, advice that may be well worth taking.

TOPICS
Michelle Fitzsimmons

Michelle was previously a news editor at TechRadar, leading consumer tech news and reviews. Michelle is now a Content Strategist at Facebook.  A versatile, highly effective content writer and skilled editor with a keen eye for detail, Michelle is a collaborative problem solver and covered everything from smartwatches and microprocessors to VR and self-driving cars.

Latest in Twitter
Cartoon of Elon Musk with flaming dollar bills in the background
Elon Musk plans to charge new X users $1 to use the app, so I guess I’m really done with Twitter now
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Elon Musk has removed a vital feature on X – fake news could soon get a lot worse
Cartoon of Elon Musk with flaming dollar bills in the background
Elon Musk continues campaign to ruin his own platform by removing Twitter Circles
A phone screen showing the Twitter Blue logo
Twitter's Blue Ticks are now so toxic that paid users can choose to hide them
X logo and Twitter logo with arrows showing swap
Sorry, Elon Musk, I signed up for Twitter, not X. Now it's time to go
Angry about Twitter Blue Checks
Your Twitter settings may no longer allow DMs - here's how to change it
Latest in News
Metroid Prime 4
I reckon the Nintendo Switch 2 could launch with Metroid Prime 4 – here’s why
Samsung Galaxy Z Fold 6
New rumors predict a foldable iPhone will launch next year – and cost almost twice as much as the iPhone 16 Pro Max
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
Nintendo Switch 2
Nintendo Switch 2 expected to have AI upscaling and I can't wait to finally play Tears of the Kingdom with upgraded graphics