What we know about the #Twitter "data leak" so far [a neat summary]:
1. Well, basically it wasn't a leak per se, as the #data was being scraped.
2. The data was collected [scraped] in December 2021 using a Twitter API vulnerability.
3. The vulnerability was fixed in January 2022.
4. The scraped data contains emails and phone numbers of 400 million Twitter users.
5. Someone calling themselves "Ryushi" say they're behind all this, now claiming to be selling the data.
A great opportunity for cyber criminals to take advantage of all this by sending phishing emails or calling stating that:
A) Your Twitter account is suspended or
B) There are some login issues, prompting you to login on to a non-Twitter domain 🎣📧
So stay vigilant, people. #cyberattack #phishing #cybercriminality