Twitter data breach shows APIs are a goldmine for PII and social engineering 

Check out all the on-demand sessions from the Intelligent Security Summit here.


A Twitter API vulnerability shipped in June 2021 (and later patched) has come back to haunt the organization. In December, one hacker claimed to have the personal data of 400 million users for sale on the dark web, and just yesterday, attackers released the account details and email addresses of 235 million users for free. 

Information exposed as part of the breach include users’ account names, handles, creation date, follower count and email addresses. When put together, threat actors can create social engineering campaigns to trick users into handing over their personal data. 

While the information exposed was limited to users’ publicly available information, the high-volume of accounts exposed in a single location provides threat actors with a goldmine of information they can use to orchestrate highly targeted social engineering attacks. 

Social media giants offer cybercriminals a gold mine of information they can use to conduct social engineering scams. 

Event

Intelligent Security Summit On-Demand

Learn the critical role of AI & ML in cybersecurity and industry specific case studies. Watch on-demand sessions today.


Watch Here

With just a name, email address and contextual information taken from a user’s public profile, a hacker can conduct reconnaissance on a target and develop purpose-built scams and phishing campaigns to trick them into handing over personal information.

“This leak essentially doxxes the personal email addresses of high-profile users (but also of regular users), which can be used for spam harassment and even attempts to hack those accounts,” said Miklos Zoltan, Privacy Affairs security researcher. “High-profit users may get inundated with spam and phishing attempts on a mass scale.”

For this reason, Zoltan recommends that users create different passwords for each site they use to reduce the risk of account takeover attempts.

Insecure APIs provide cybercriminals with a direct line to access user’s personally identifiable information (PII), usernames and passwords, which are captured when a client makes a connection to a third-party service’s API. Thus, API attacks provide attackers with a window to harvest personal data for scams en masse. 

This happened just a month ago when a threat actor successfully applied to the FBI’s InfraGuard intelligence sharing service, and used an API vulnerability to collect the data of 80,000 executives across the private sector and put it up for sale on the dark web. 

Information collected during the incident included data such as usernames, email addresses, Social Security numbers and dates of birth — all highly valuable information for developing social engineering scams and spear phishing attacks. 

Unfortunately, it appears that this trend of API exploitation will only get worse, with Gartner predicting that this year, API abuse will become the most frequent attack vector. 

Beyond APIs that ‘just work’

Organizations too are increasingly concerned around API security, with 94% of technology decision-makers reporting they are only moderately confident in their organization’s ability to materially reduce API data security issues. 

From now on, enterprises that leverage APIs need to be much more proactive about baking security into their products, while users need to take extra caution around potentially malicious emails. 

“This is a common example of how an unsecured API that developers design to ‘just work’ can remain unsecured, because when it comes to security, what is out-of-sight is often out-of-mind,” said Jamie Boote, associate software security consultant at Synopsys Software Integrity Group. “From now on, it’s probably best to just delete any emails that look like they’re from Twitter to avoid phishing scams.” 

Protecting APIs and PII 

One of the core challenges around addressing API breaches is the fact that modern enterprises need to discover and secure thousands of APIs.  

“Protecting organizations from API attacks requires consistent, diligent oversight of vendor management, and specifically ensuring that every API is fit for use,” said Chris Bowen, CISO at ClearDATA. “It’s a lot for organizations to manage, but the risk is too great not to.”

There’s also a slim margin for error, as a single vulnerability can put user data directly at risk of exfiltration. 

“In healthcare, for example, where patient data is at stake, every API should address several components like identity management, access management, authentication, authorization, data transport and exchange security, and trusted connectivity,” said Bowen. 

It’s also important that security teams not make the mistake of relying solely on simple authentication options such as usernames and passwords to protect their APIs. 

“In today’s environment, basic usernames and passwords are no longer enough,” said Will Au, senior director for DevOps, operations and site reliability at Jitterbit. “It’s now vital to use standards such as two-factor authentication (2FA) and/or secure authentication with OAuth.”

Other steps like deploying a Web Application Firewall (WAF), and monitoring API traffic in real-time can help to detect malicious activity and reduce the chance of compromise. 

VentureBeat’s mission is to be a digital town square for technical decision-makers to gain knowledge about transformative enterprise technology and transact. Discover our Briefings.

Read More
Tim Keary

Latest

Broncos football player arrested for second time in 8 days

Broncos football player arrested for second time in 8 days Denver Broncos linebacker Jonathon Cooper is facing additional legal trouble after authorities arrested him for allegedly violating a court-issued protection order connected to an ongoing domestic violence case. According to police, Cooper was taken into custody after allegedly contacting and visiting his girlfriend despite being

NFL vs. College Football: Highest Earnings by Position in New NIL Era

NFL vs. College Football: Highest Earnings by Position in New NIL Era The gap between professional and college football earnings remains substantial, even as NIL opportunities have transformed the landscape for elite college athletes. According to Football Scoop and NIL Standard, top NFL players still earn significantly more than the highest-paid college players at the

Deion Sanders Received Bonus He Didn’t Earn as Colorado’s $1.2M Blunder Surfaces: Report

When CU brought Deion Sanders in 2023, it was not just for football. It was also a business move. He brought cameras, celebrities, huge television ratings, and a level of attention that Colorado had not seen in decades. Quickly, CU got attention, and it helped explain why the program rewarded Sanders with a $250,000 discretionary

Moving Yahya Black To Nose Tackle Isn’t A Seismic Change

According to accounts from the Pittsburgh Steelers’ coaching staff and beat writers attending spring practices, Yahya Black is playing nose tackle. New defensive line coach Domata Peko suggested Black could become one of football’s best nose tackles. It’s a different framing than a year ago, when Pittsburgh’s old regime viewed Black as a defensive end

Newsletter

Don't miss

Broncos football player arrested for second time in 8 days

Broncos football player arrested for second time in 8 days Denver Broncos linebacker Jonathon Cooper is facing additional legal trouble after authorities arrested him for allegedly violating a court-issued protection order connected to an ongoing domestic violence case. According to police, Cooper was taken into custody after allegedly contacting and visiting his girlfriend despite being

NFL vs. College Football: Highest Earnings by Position in New NIL Era

NFL vs. College Football: Highest Earnings by Position in New NIL Era The gap between professional and college football earnings remains substantial, even as NIL opportunities have transformed the landscape for elite college athletes. According to Football Scoop and NIL Standard, top NFL players still earn significantly more than the highest-paid college players at the

Deion Sanders Received Bonus He Didn’t Earn as Colorado’s $1.2M Blunder Surfaces: Report

When CU brought Deion Sanders in 2023, it was not just for football. It was also a business move. He brought cameras, celebrities, huge television ratings, and a level of attention that Colorado had not seen in decades. Quickly, CU got attention, and it helped explain why the program rewarded Sanders with a $250,000 discretionary

Moving Yahya Black To Nose Tackle Isn’t A Seismic Change

According to accounts from the Pittsburgh Steelers’ coaching staff and beat writers attending spring practices, Yahya Black is playing nose tackle. New defensive line coach Domata Peko suggested Black could become one of football’s best nose tackles. It’s a different framing than a year ago, when Pittsburgh’s old regime viewed Black as a defensive end

Navy Coach Shares Why ‘Gritty Guy’ Eli Heidenreich Can Carve Out Special Teams Role With Steelers

Making a 53-man roster in the NFL is a tough task, especially for a seventh-round pick. It’s a long, challenging road, and the odds are stacked against you. So, the more you can do for a football team, the better. Pittsburgh Steelers rookie running back and wide receiver Eli Heidenreich has the advantage of being

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID

Business groups are fighting Labor’s CGT changes. Here is where SMEs stand

Labor’s most contested tax reform in a generation cleared its first formal hurdle on Thursday and immediately ran into organised resistance. Treasurer Jim Chalmers introduced the government’s tax reform legislation to the House of Representatives on 28 May, bundling together four budget measures: the capital gains tax overhaul, new limits on negative gearing, a $250

Meet the most influential business owners from Southwest Nigeria

This article spotlights the most influential business owners from Southwest Nigeria, adjudged by their dominance in their respective sectors of the economy where they operate. The post Meet the most influential business owners from Southwest Nigeria appeared first on Nairametrics...