When Twitter revealed Friday that 250,000 of its user accounts may have been compromised by hackers, it downplayed the damage by adding that “only a very small percentage” of users were affected. But that very small percentage may represent a very big chunk of Twitter’s activity and influence.
The quarter million Twitterers hit by the hacker compromise were nearly all among the first batch of users of Twitter’s service, registered in June of 2007 or earlier, according to an analysis by the social media analytics firm PeerReach and others by independent Twitter users. PeerReach found that among 80 users it asked or who volunteered the information on Twitter, all but four who were alerted that their account was compromised had registered in that early window, and every user that hadn’t received the email had registered later. Another count of 54 users by Melissa Elliott, a researcher with security firm Veracode working in her spare time, found that all but one user hit by the attack had registered before the same cutoff date, and I got similar results when I queried another dozen Twitter users.
If the 250,000 hacking victims were in fact the first to register on Twitter, that also makes them some of the site’s most high-profile and active users. Using June 15th, 2007 as the estimated cutoff date for the targets of the Twitter hack, PeerReach found that the hacking victims likely included President Barack Obama, Vice President Joe Biden, Speaker of the House John Boehner, and Congressman Eric Cantor, among other politicians. (None of them responded to tweets I sent to their accounts asking about the security breach.)
“Twitter is saying that only a tenth of a percent of their total population has been compromised. But this tenth of a percent is among the most significant,” says PeerReach analyst Nico Schoonderwoerd. “This could be coincidence, or it could be they specifically targeted a certain server because they specifically wanted to access those accounts.”
PeerReach also checked its list of what it considers the top one hundred most influential media Twitterers and found that 22% were likely included in the compromised accounts, including the main accounts for the New York Times, CNN, NPR, Reuters, the BBC, and the Guardian.
More importantly, perhaps, are the reporters themselves among those accounts, who may have had their private communications with sources violated; They include the New York Times’ Nick Bilton, MSNBC’s Chris Hayes, and CBS‘s John Dickerson. Given that Twitter alluded in its blog post to a string of recent attacks allegedly carried out by Chinese hackers, it’s worth noting that many well-known Chinese and China-focused bloggers were among the early set of Twitter users, too, including Michael Anti, Isaac Mao, and Bill Bishop.
Twitter hasn’t offered many details about its breach, other than warning affected users that their usernames, email addresses, and hashed passwords were all potentially stolen by hackers, along with the session tokens that allow users to access the service without logging in on every visit. The company has forced all affected users to change their passwords and reset their session tokens. Compromised users should be sure to also change the password of any accounts on other services where they used the same login credentials. The company hasn’t revealed when it was first hacked, and didn’t immediately respond to my request for more information Monday.
In its blog post about the compromise last week, Twitter asked users to be wary of phishing websites and disable Java in their browsers. Those measures would prevent so-called “client-side attacks” that take place on users’ machines when they visit a malicious websites. But the fact that only Twitter’s first batch of users were affected means that it’s far more likely the data was stolen from Twitter’s servers, where it was organized by date.
“It seems much more likely that something happened on Twitter’s backend than on any client,” says Veracode’s Melissa Elliot. “They’re being very coy about it.”
See PeerReach’s full analysis here.
Related:
–
Follow me on Twitter, and check out my new book, This Machine Kills Secrets: How WikiLeakers, Cypherpunks and Hacktivists Aim To Free The World’s Information.















President Obama has STOPPED the oil leak in the gulf! The oil spill is over! Is it too much for him to take a little break to celebrate his accomplishment?
I am willing to begin a petition drive, walk across America, or do whatever it may take to ensure that President Obama serves us for the rest of his life. We would perish without his careful touch as the good ship America maneuvers the wretched waters…just ahead.
How do I begin the process, please? I’m retired, and can fund it myself. But I need to know how. I want it to be effective.
President Obama is talking to regular people about the real problems that this country is currently facing. I think this is absolutely the right direction for this country.
There is many of large oil discoveries in the gulf of mexico, but President Obama will not any new leases. Is he waiting on $7.00 a gallon gas?
Do you think President Obama did the right thing in ordering the SEALS to act in the pirate situation, if so, why?
If you don’t think this was right thing to-do please explain also.
Two Senate bills No. 773 and 778 will grant President Obama the power to access private data, create an office of internet control and the power to shut down whole internet networks in case of a cyber-emergency.Who believes this is a good idea and why?
Theres a knock at the door…you open it…..president Obama is standing there and grinning at you…he pauses for a moment and then starts licking his lips. What you gonna do?
Rosemary B – Is “returning the smile and welcoming him into your home” a euphemism?
What is President Obama doing to encourage people to become productive, self-reliant, hard working , motivated achievers instead of becoming unproductive, lazy, unmotivated underachievers who always rely upon the government for their wants & needs ?
What is President Obama doing to encourage people to try to find a job and try to get off welfare ?
Rolando – how does ” lowering taxes for small businesses ” encourage unproductive people who are on welfare for whatever reason to become productive people by finding and working at a job ?
1. What is the basic difference in approach between President Bush and President Obama’s administrations to solving the economic crisis in the US?
2. Which do you think would be most effective? Why?
There is a policy against degrading our Commander in Chief, President Obama. What punishment should I give my troop? Should I let it go with just a warning? Should I take it up the chain of command?
He basically made racist statements like those you find on Yahoo answers from some extreme right conservatives.
More than 90,000 Troops have been taken out of Iraq since President Obama took office.
Many of you said that he would never keep his August 31 deadline, but he did it. But unlike Bush, he does not declare “Mission Accomplished”, he just moves on to the next challenge.
who can please tell me when president Obama is going to start working for America. So far all he has done is apologize for america being so bad. I think history proves that America is great, and if not for us the rest of the world would not have improved.
What happened to loyalty to America first?
If Democrats had done that, then they would have been called Anti-American.
President Obama’s stance on Israel is the exact same stance as George W. Bush’s Stance.
President Obama, the current president of the USA, is challenging the countries to hope and change just like we were asked to about a year or so ago. What countries do you think will take on this challenge? Which ones will not? How can you make your country better?
Is President Obama daring us to revolt? Would a revolution give President Obama and all the other progressives a good reason to fire upon and arrest US citizens who oppose him?