• Home
  • News
  • Fortune 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Tech

Millions Of Twitter Users May Have Been Hacked

By
David Meyer
David Meyer
Down Arrow Button Icon
By
David Meyer
David Meyer
Down Arrow Button Icon
June 9, 2016, 7:02 AM ET
Illustrations Of Popular Mobile Apps And Social Media Sites
People are seen as silhouettes as they check mobile devices whilst standing against an illuminated wall bearing Twitter Inc.'s logo in this arranged photograph in London, U.K., on Tuesday, Jan. 5, 2016. Twitter Inc. may be preparing to raise its character limit for tweets to the thousands from the current 140, a person with knowledge of the matter said. Photographer: Chris Ratcliffe/Bloomberg via Getty ImagesChris Ratcliffe—Bloomberg via Getty Images

The credentials of more than 32 million Twitter (TWTR) users have reportedly been stolen and leaked—but with this particular mega-breach, the twist is that it doesn’t seem to have been Twitter itself that was the source of the data.

There has recently been a spate of user credentials from services such as LinkedIn (LNKD) and MySpace turning up in the online underground, but in each of these cases the data appeared to have come from a breach of the service provider’s systems—a tell-tale sign being that the passwords were (badly) encrypted.

Those breaches become public through a shadowy site called LeakedSource, that lets people see whether their credentials have been included in particular leaked datasets. LeakedSource is again the conduit for this latest tranche of data, but its proprietors reckon the Twitter credentials were stolen from the users’ browsers. Twitter is also adamant that it wasn’t itself hacked.

Get Data Sheet, Fortune’s technology newsletter.

“We are confident that these usernames and credentials were not obtained by a Twitter data breach—our systems have not been breached,” Twitter said in a statement. “In fact, we’ve been working to help keep accounts protected by checking our data against what’s been shared from recent other password leaks.”

In a blog post, LeakedSource said the dataset included passwords from people who had signed up to Twitter as recently as 2014, but the passwords had been stored in “plaintext,” with no attempt to encrypt them. In line with being a large, prominent web firm, Twitter isn’t so careless with its customers’ data.

As Twitter information security officer Michael Coates tweeted:

We securely store all passwords w/ bcrypt. We are working with @leakedsource to obtain this info & take additional steps to protect users.

— Michael Coatesۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗ (@_mwc) June 9, 2016

What’s more, LeakedSource said many passwords in the dataset were listed as “blank,” which is how browsers refer to a user’s password when the user doesn’t choose to store their password along with their login credentials.

In short, according to LeakedSource’s theory, whoever stole this data apparently stole it from the users’ browsers. This was most probably done with malware, and it seems to have disproportionately targeted Russians—the most common email address domain in the list is “mail.ru,” with five other Russian email providers also appearing in the top 10.

If that’s the case, the thieves probably took more than just Twitter credentials.

For more on cybersecurity, watch our video.

“These credentials…are real and valid. Out of 15 users we asked, all 15 verified their passwords,” LeakedSource wrote. “The explanation for this is that tens of millions of people have become infected by malware, and the malware sent every saved username and password from browsers like Chrome and Firefox back to the hackers from all websites including Twitter.”

Russia was also the focus of the last big stolen-data leak that showed up on LeakedSource a few days ago—that time round, the target was VK, the country’s biggest social network.

If LeakedSource’s account checks out and you’re a victim, it’s probably a good idea to get rid of that malware, not just change your password. When someone has access to a computer in this way, they can use it to steal information and propagate the malware to other people.

https://twitter.com/LeakedSource/status/740748213926367233

According to ZDNet, the hacker who provided the Twitter data to LeakedSource (as well as the MySpace and VK data) is now trying to sell it for 10 bitcoins (around $5,800).

It does seem like a regular theme for LeakedSource to be announcing major leaks at the same time as people show up on underground marketplaces trying to sell the relevant data. The timing isn’t about the leaks themselves, as those have taken place over years, although the data is all surfacing now. LeakedSource claims it “does not engage in, encourage or condone” hacking.

About the Author
By David Meyer
LinkedIn icon
See full bioRight Arrow Button Icon

Latest in Tech

Big TechSpotify
Spotify users lamented Wrapped in 2024. This year, the company brought back an old favorite and made it less about AI
By Dave Lozo and Morning BrewDecember 4, 2025
50 minutes ago
InnovationVenture Capital
This Khosla Ventures–backed startup is using AI to personalize cancer care
By Allie GarfinkleDecember 4, 2025
5 hours ago
AIEye on AI
Companies are increasingly falling victim to AI impersonation scams. This startup just raised $28M to stop deepfakes in real time
By Sharon GoldmanDecember 4, 2025
5 hours ago
Jensen Huang
SuccessBillionaires
Nvidia CEO Jensen Huang admits he works 7 days a week, including holidays, in a constant ‘state of anxiety’ out of fear of going bankrupt
By Jessica CoacciDecember 4, 2025
6 hours ago
Ted Pick
BankingData centers
Morgan Stanley considers offloading some of its data-center exposure
By Esteban Duarte, Paula Seligson, Davide Scigliuzzo and BloombergDecember 4, 2025
6 hours ago
Zuckerberg
EnergyMeta
Meta’s Zuckerberg plans deep cuts for Metaverse efforts
By Kurt Wagner and BloombergDecember 4, 2025
6 hours ago

Most Popular

placeholder alt text
Economy
Two months into the new fiscal year and the U.S. government is already spending more than $10 billion a week servicing national debt
By Eleanor PringleDecember 4, 2025
11 hours ago
placeholder alt text
North America
Jeff Bezos and Lauren Sánchez Bezos commit $102.5 million to organizations combating homelessness across the U.S.: ‘This is just the beginning’
By Sydney LakeDecember 2, 2025
2 days ago
placeholder alt text
Success
‘Godfather of AI’ says Bill Gates and Elon Musk are right about the future of work—but he predicts mass unemployment is on its way
By Preston ForeDecember 4, 2025
6 hours ago
placeholder alt text
Economy
Ford workers told their CEO 'none of the young people want to work here.' So Jim Farley took a page out of the founder's playbook
By Sasha RogelbergNovember 28, 2025
6 days ago
placeholder alt text
North America
Anonymous $50 million donation helps cover the next 50 years of tuition for medical lab science students at University of Washington
By The Associated PressDecember 2, 2025
2 days ago
placeholder alt text
AI
IBM CEO warns there’s ‘no way’ hyperscalers like Google and Amazon will be able to turn a profit at the rate of their data center spending
By Marco Quiroz-GutierrezDecember 3, 2025
1 day ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.