• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Tech

Twitter Warns 336 Million Users to Change Their Passwords After Leaving Them Vulnerable to Hackers

By
Jonathan Vanian
Jonathan Vanian
Down Arrow Button Icon
By
Jonathan Vanian
Jonathan Vanian
Down Arrow Button Icon
May 3, 2018, 6:32 PM ET

Twitter warned its users on Thursday to change their passwords after it discovered that it had mistakenly stored them internally prior to fortifying them through a security technique, leaving the passwords vulnerable to hackers.

Parag Agrawal, Twitter’s chief technology officer, wrote in a blog post that users should also consider changing their passwords on other services if the passwords they used there were the same as on Twitter. The company also disclosed the password flaw in a regulatory filing on Thursday, indicating that the bug was serious enough to warrant more formal disclosure than a corporate blog post. Twitter has about 336 million users, according to its latest letter to shareholders.

Twitter (TWTR) CEO Jack Dorsey followed Agrawal’s post by tweeting that company has “no indication of breach or misuse.” He added that the company warned users because “it’s important for us to be open about this internal defect.”

The software bug said to be responsible for the problem appears to be related to how the company secures user passwords through a security technique called hashing, Agrawal explained. Through the hashing technique, Twitter converts passwords into random assortments of numbers so that when users log in, Twitter can validate passwords without actually having to read them.

Because of the software bug, however, user passwords were written into an unspecified “internal log” before they could be converted into a series of numbers. As a result, user passwords were left vulnerable, although Twitter said no one appears to have improperly accessed the log.

We recently discovered a bug where account passwords were being written to an internal log before completing a masking/hashing process. We’ve fixed, see no indication of breach or misuse, and believe it’s important for us to be open about this internal defect. https://t.co/BJezo7Gk00

— jack (@jack) May 3, 2018

Agrawal said that Twitter discovered the error without the help of outside security researchers, removed the passwords from the internal log, and is “implementing plans” to prevent future errors.

It’s unclear when Twitter found out about the problem or how long the passwords were left unsecured. Fortune contacted Twitter for more details and will update this story if it responds.

Ironically, Twitter’s password mishap was announced on the corporate holiday known as World Password Day, created by Intel security researchers and celebrated on the first Thursday in May as a way to promote good password and cyber security hygiene.

Get Data Sheet, Fortune’s technology newsletter.

Agrawal initially said via a Tweet that the company “didn’t have to” share the information to the public, but chose to because “it’s the right thing to do.” However, he then backtracked on his statement and said that he “felt strongly that we should.” “My mistake,” Agrawal added.

Dorsey then commended him for “admitting our mistakes quickly, learning, and moving on.”

Openly admitting our mistakes quickly, learning, and moving on. I love my teammates. https://t.co/pn9sgUf1Op

— jack (@jack) May 3, 2018

I should not have said we didn’t have to share. I have felt strongly that we should. My mistake. https://t.co/Cqbs1KiUWd

— Parag Agrawal (@paraga) May 3, 2018

We are sharing this information to help people make an informed decision about their account security. We didn’t have to, but believe it’s the right thing to do. https://t.co/yVKOqnlITA

— Parag Agrawal (@paraga) May 3, 2018

 

“We are very sorry this happened,” Agrawal wrote in his blog post. “We recognize and appreciate the trust you place in us, and are committed to earning that trust every day.”

About the Author
By Jonathan Vanian
LinkedIn iconTwitter icon

Jonathan Vanian is a former Fortune reporter. He covered business technology, cybersecurity, artificial intelligence, data privacy, and other topics.

See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Exclusive: Senator presses DOJ and Treasury over status of Binance monitors after $1.7 billion in Iran-linked crypto flows
CryptoIran
Exclusive: Senator presses DOJ and Treasury over status of Binance monitors after $1.7 billion in Iran-linked crypto flows
By Ben WeissApril 17, 2026
10 minutes ago
The world holds its breath: Trump says Iran war will end ‘pretty soon’ as uranium deal is in sight
EconomyMarkets
The world holds its breath: Trump says Iran war will end ‘pretty soon’ as uranium deal is in sight
By Jim EdwardsApril 17, 2026
1 hour ago
The startup Blackstone just backed to turn any exec’s data question into instant answers
NewslettersTerm Sheet
The startup Blackstone just backed to turn any exec’s data question into instant answers
By Allie GarfinkleApril 17, 2026
2 hours ago
Netflix cofounder and chairman Reed Hastings on July 10, 2025 in Sun Valley, Idaho. (Photo: Kevin Dietsch/Getty Images)
NewslettersFortune Tech
End of an era: Reed Hastings steps down from Netflix
By Andrew NuscaApril 17, 2026
2 hours ago
A secretive tycoon known as the ‘French Murdoch’ holds the key to Bill Ackman’s $64 billion bid for Universal Music Group
Personal FinanceInvestment
A secretive tycoon known as the ‘French Murdoch’ holds the key to Bill Ackman’s $64 billion bid for Universal Music Group
By Amanda GerutApril 17, 2026
4 hours ago
Teen boys are dating their AI chatbots—and experts warn opting out of real relationships could hurt their careers in the future
SuccessThe Promotion Playbook
Teen boys are dating their AI chatbots—and experts warn opting out of real relationships could hurt their careers in the future
By Orianna Rosa RoyleApril 17, 2026
4 hours ago

Most Popular

Jeff Bezos pledged $10 billion for climate change. With the 2030 clock ticking, his wife, Lauren Sánchez Bezos, is leading the charge to spend it
Environment
Jeff Bezos pledged $10 billion for climate change. With the 2030 clock ticking, his wife, Lauren Sánchez Bezos, is leading the charge to spend it
By Sydney LakeApril 15, 2026
2 days ago
A world going broke: IMF says America's $39 trillion national debt is actually a global problem—and AI may be the only rescue
Economy
A world going broke: IMF says America's $39 trillion national debt is actually a global problem—and AI may be the only rescue
By Nick LichtenbergApril 16, 2026
16 hours ago
Germany already told its workers to ditch four-day weeks and work-life balance. Now the government wants to cut their pay for calling in sick, too
Success
Germany already told its workers to ditch four-day weeks and work-life balance. Now the government wants to cut their pay for calling in sick, too
By Orianna Rosa RoyleApril 16, 2026
1 day ago
MacKenzie Scott is bypassing the Ivy League and rewriting the $79 billion higher ed playbook by giving to HBCUs and community colleges
Politics
MacKenzie Scott is bypassing the Ivy League and rewriting the $79 billion higher ed playbook by giving to HBCUs and community colleges
By Sydney LakeApril 16, 2026
20 hours ago
Current price of oil as of April 16, 2026
Personal Finance
Current price of oil as of April 16, 2026
By Joseph HostetlerApril 16, 2026
23 hours ago
Billionaire philanthropist MacKenzie Scott has donated again—a week after gifting millions to a college, she's just given $70 million to Meals on Wheels America
Success
Billionaire philanthropist MacKenzie Scott has donated again—a week after gifting millions to a college, she's just given $70 million to Meals on Wheels America
By Emma BurleighApril 13, 2026
4 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.