'Some structural damage' from wildfire near Fort Nelson, B.C., mayor confirms
More than one home has been damaged or lost due to a massive wildfire outside of the B.C. community of Fort Nelson, the mayor confirmed Wednesday.
Email addresses linked to more than 200 million Twitter profiles are currently circulating on underground hacker forums, security experts say. The apparent data leak could expose the real-life identities of anonymous Twitter users and make it easier for criminals to hijack Twitter accounts, the experts warned, or even victims' accounts on other websites.
The trove of leaked records also includes Twitter users' names, account handles, follower numbers and the dates the accounts were created, according to forum listings reviewed by security researchers and shared with CNN.
"Bad actors have won the jackpot," said Rafi Mendelsohn, a spokesman for Cyabra, a social media analysis firm focused on identifying disinformation and inauthentic online behavior. "Previously private data such as emails, handles, and creation date can be leveraged to build smarter and more sophisticated hacking, phishing and disinformation campaigns."
Some reports suggested the data was collected in 2021 through a bug in Twitter's systems, a flaw the company fixed in 2022 after a separate incident in July involving 5.4 million Twitter accounts alerted the company to the vulnerability.
Troy Hunt, a security researcher, said Thursday that his analysis of the data "found 211,524,284 unique email addresses" that had been leaked. The Washington Post earlier reported a forum listing promoting the data of 235 million accounts.
Hunt did not immediately respond to a question from CNN asking whether the records would be added to his website, haveibeenpwned.com, which allows users to search hacked records to determine if they have been affected. CNN has not independently verified the records' authenticity.
Twitter didn't immediately respond to a request for comment. Its communication team, along with roughly half of Twitter's overall workforce, was gutted after billionaire Elon Musk completed his acquisition the company in late October. The significant staff reductions could now add to concerns about the company's ability to respond to security threats.
The breadth of the leaked data could allow malicious actors or repressive governments to connect anonymous Twitter handles with the real names or email addresses of their owners, potentially unmasking dissidents, journalists, activists or other at-risk users around the world, security researchers warn.
"For those people, this is a very consequential breach," said John Scott-Railton, a security researcher at The University of Toronto's Citizen Lab.
The account data could also be valuable to hackers who can use the information as part of password-reset attempts and account takeovers. The risk is particularly high for individuals who use the same account credentials on Twitter as they do for other digital services such as banks or cloud storage, researchers said, because hackers could take information gleaned from the leak to pry open user accounts elsewhere.
Verified Twitter users caught up in the apparent leak, or users with particularly large followings, will be particularly valuable targets as a result of the leak, security experts warned, as those account holders may be especially influential celebrities or susceptible to extortion.
To protect themselves from phishing attempts, internet users should use unique passwords for each online service and keep track of them using a digital password manager, security researchers say. They should also enable multi-factor authentication for each of their accounts, and exercise caution when opening unsolicited email or links.
According to the cybersecurity news outlet BleepingComputer, which did claim to test the data, the latest dump appears similar to a leaked dataset advertised on hacking forums in November containing an alleged 400 million records, but slimmed down to eliminate some duplicate records. Twitter has not commented on that leak.
Reports of the leak could expand Twitter's already significant legal and regulatory risk.
In December, Twitter's main European privacy regulator, the Irish Data Protection Commission, said it is investigating the July 2022 leak as a possible violation of Europe's signature privacy law, known as GDPR.
Last summer, the company's former head of security, Peiter "Mudge" Zatko, filed a whistleblower report to the US government alleging long-ignored security vulnerabilities in Twitter's operations. Zatko claimed that Twitter's shortcomings on security reflected a breach of Twitter's binding commitments to the Federal Trade Commission, a serious offense. (Twitter broadly and repeatedly pushed back at Zatko's allegations.)
Successive incidents at Twitter have led to the company signing two consent orders with the FTC since 2011 to improve its cybersecurity posture. Violations of FTC orders can lead to fines, business restrictions and even sanctions targeting individual executives.
In November, top Twitter officials responsible for privacy and security resigned from the company, just days after Musk closed his purchase of the platform and amid the mass layoffs that in some cases cut whole departments.
More than one home has been damaged or lost due to a massive wildfire outside of the B.C. community of Fort Nelson, the mayor confirmed Wednesday.
A warning from a Saskatoon driver about using your fast-food app while in the drive-thru line — a trip to get some free lunch cost him a lot more than he bargained for.
An 'unrepentant' YouTuber has been ordered to pay $350,000 in damages as compensation for a 'relentless' campaign of defamation waged online against a business owner and his company, the B.C. Supreme Court has ruled.
Chief Robert Michell says relief isn't the right word to describe his reaction as the search begins for unmarked graves at the site of a former residential school he attended in northern British Columbia.
While it's unclear what these closures might mean for the 27 restaurants in Canada, Red Lobster is expected to file for bankruptcy protection in the U.S. this month.
A man from B.C.'s Lower Mainland has been sentenced to four years behind bars after shooting a sex worker in the back during a drug-fuelled 43rd birthday.
Nearly six dozen dogs were seized from a home Wednesday morning by the Winnipeg Humane Society. It is the largest known seizure of animals in the city’s history.
Of the $40-million Aiden Pleterski was handed over two years, documents show he invested just over one per cent and instead spent $15.9 million on "his personal lifestyle." The 25-year-old Oshawa, Ont. man was arrested and charged with fraud and money laundering on Tuesday.
A man with a long record of dangerous driving told investigators he smoked marijuana oil and took prescription drugs hours before he sideswiped a bus, killing eight Mexican farmworkers and injuring dozens more, according to an arrest report unsealed Wednesday.
When Adam Kirschner wrote 'Slap Shot,' he never imagined the song would be embraced by his favourite team.
A team is ready to help an entangled North Atlantic right whale in the Gulf of St. Lawrence.
A $200 reward is being offered by a North Vancouver family for the safe return of their beloved chicken, Snowflake.
Two daughters and a mother were reunited online 40 years later thanks to a DNA kit and a Zoom connection despite living on three separate continents and speaking different languages.
Mother's Day can be a difficult occasion for those who have lost or are estranged from their mom.
YES Theatre Young Company opened its acclaimed kids’ show, One Small Step, at Sudbury Theatre Centre on Saturday.
An Ottawa pizzeria is being recognized as one of the top 20 deep-dish pizzas in the world.
A family of fifth generation farmers from Ituna, Sask. are trying to find answers after discovering several strange objects lying on their land.
A Listowel, Ont. man, drafted by the Hamilton Tigercats last week, is also getting looks from the NFL, despite only playing 27 games of football in his life.