Twitter says hackers compromise 250K accounts

Feb 02, 2013 by Terry Collins
In this Sept. 14, 2010 file photo, Twitter CEO Evan Williams makes a presentation about changes to the social network at Twitter headquarters in San Francisco, In the latest online attack, Twitter says hackers may have gained access to information on 250,000 of its more than 200 million active users, Friday, Feb. 1, 2013. (AP Photo/Marcio Jose Sanchez, File)

Twitter confirmed Friday that it had become the latest victim in a number of high-profile cyber-attacks against media companies, saying that hackers may have gained access to information on 250,000 of its more than 200 million active users.

The social said in a blog posting that earlier this week it detected attempts to gain access to its user data. It shut down one attack moments after it was detected.

But it discovered that the attackers may have stolen user names, email addresses and belonging to 250,000 users. Twitter reset the pilfered passwords and sent emails advising affected users.

The online attack comes on the heels of recent hacks into the computer systems of U.S. media and , including The and The . Both American newspapers reported this week that their computer systems had been infiltrated by China-based hackers, likely to monitor the deems important.

China has been accused of mounting a widespread, aggressive cyber-spying campaign for several years, trying to steal classified information and corporate secrets and to intimidate critics. The Chinese could not be reached for comment Saturday, but the Chinese government has said those accusations are baseless and that China itself is a victim of cyber-attacks.

"Chinese law forbids hacking and any other actions that damage Internet security," the Chinese recently said. "The Chinese military has never supported any hacking activities."

Although Twitter said in its blog that the attack "was not the work of amateurs, and we do not believe it was an isolated incident."

"The attackers were extremely sophisticated, and we believe other companies and organizations have also been recently similarly attacked," the blog said. "For that reason we felt that it was important to publicize this attack while we still gather information, and we are helping government and federal law enforcement in their effort to find and prosecute these attackers to make the Internet safer for all users."

One expert said that the Twitter hack probably happened after an employee's home or work computer was compromised through vulnerabilities in Java, a commonly used computing language whose weaknesses have been well publicized.

Ashkan Soltani, an independent privacy and security researcher, said such a move would give attackers "a toehold" in Twitter's internal network, potentially allowing them either to sniff out user information as it traveled across the company's system or break into specific areas, such as the authentication servers that process users' passwords.

In a telephone interview Friday, Soltani said that the relatively small number of users affected suggested either that attackers weren't on the network long or that they were only able to compromise a subset of the company's servers.

Twitter is generally used to broadcast messages to the public, so the hacking might not immediately have yielded any important secrets. But the stolen credentials could be used to eavesdrop on private messages or track which Internet address a user is posting from.

That might be useful, for example, for an authoritarian regime trying to keep tabs on a journalist's movements.

"More realistically, someone could use that as an entry point into another service," Soltani said, noting that since few people bother using different passwords for different services, a password stolen from Twitter might be just as handy for reading a journalist's emails.

Explore further: NY Times says Chinese hacked paper's computers (Update)

5 /5 (1 vote)
add to favorites email to friend print save as pdf

Related Stories

NY Times says Chinese hacked paper's computers (Update)

Jan 31, 2013

Chinese hackers repeatedly penetrated The New York Times' computer systems over the past four months, stealing reporters' passwords and hunting for files on an investigation into the wealth amassed by the family of a top ...

Google adds warning of 'state-sponsored attacks'

Jun 06, 2012

(AP) — Google said Wednesday that it has added a feature to warn users whose accounts it believes are targets of "state-sponsored attacks," but the Internet giant did not cite a specific government.

Recommended for you

Kim Dotcom slams Megaupload 'data massacre'

10 hours ago

Megaupload founder Kim Dotcom Thursday condemned a Dutch company's decision to delete million of files belonging to users of his defunct website, calling it "the largest data massacre in the history of the ...

States scramble to attract suddenly hot cybersecurity firms

18 hours ago

As data dragnets and information breaches dominate the news, states are scrambling to cash in on a rapidly expanding business sector by offering tax incentives to firms that protect sensitive information from outside attacks.

A year on, Assange stays put in Ecuadorean Embassy

Jun 19, 2013

A year ago, Julian Assange skipped out on a date with Swedish justice. Rather than comply with a British order that he go to the Scandinavian country for questioning about sex crimes allegations, the WikiLeaks ...

Google asks US secret court to lift gag order (Update)

Jun 18, 2013

Google on Tuesday sharply challenged the U.S. government's gag order on its Internet surveillance program, citing what it described as a constitutional free speech right to divulge how many requests it receives ...

User comments : 0

More news stories

AP buys stake in live video service Bambuser

The Associated Press said Thursday that it has bought a minority stake in the live video service Bambuser, boosting its ability to acquire and distribute video collected by people who have witnessed news events.

Sony chief says time needed to study proposal

Sony Corp. needs more time to study a key proposal from a U.S. hedge fund to spin off a part of its entertainment unit as a way to propel its fledgling revival, the chief executive told shareholders Thursday.

Panic over MERS virus fades in Saudi

People in Saudi Arabia's Eastern Province have again started greeting friends with the traditional kiss on the cheek, and face masks in public are becoming rarer, as panic subsides over the outbreak of a deadly respiratory ...

S.Korean airlines ban shark fin as cargo

South Korea's two largest airlines, Korean Air and Asiana, said Thursday they had both decided to ban shark fin from their cargo flights as part of a growing global campaign against the Asian delicacy.

UNESCO warns Syrian heritage sites endangered

UNESCO on Thursday added six ancient sites in Syria including a fortress of Saladin and a Crusader castle to the endangered World Heritage list, warning that more than two years of civil war had inflicted ...

Philippines financial capital bans plastic bags

The Philippines financial capital banned disposable plastic shopping bags and styrofoam food containers on Thursday, as part of escalating efforts across the nation's capital to curb rubbish that exacerbates ...

Singapore haze at worst yet, Malaysia schools shut

Singapore urged people to remain indoors amid unprecedented levels of air pollution Thursday as a smoky haze wrought by forest fires in neighboring Indonesia worsened dramatically. Nearby Malaysia closed ...