Twitter investigating giant password leak, suggests it may be much ado about nothing

Twitter (zpower)

It looked like a massive breach: yesterday, a tremendous list of over 56,000 Twitter IDs and passwords were set loose on the internet. Today, Twitter has confirmed a leak and says it's actively investigating, but a company spokesperson says the impact may not be as big as you'd expect. According to Twitter, a huge number of those IDs appear to be duplicates of one another, others are accounts that were already suspended for spamming, and many of the passwords seem to be wholly incorrect. That statement seems to line up with what we're seeing, too.

While that's small comfort if your account was among those whose password was leaked, and doesn't actually explain the apparent breach, we haven't seen or heard proof that active users have had their accounts compromised as of yet. Also, Twitter says it's proactively sending some users requests to change their password in case they might have been affected. We'll be keeping tabs on this story and will let you know if that changes, or if Twitter tells us how the leak occurred in the first place. In the meanwhile, find Twitter's full statement below.

We are currently looking into the situation. In the meantime, we have pushed out password resets to accounts that may have been affected. For those who are concerned that their account may have been compromised, we suggest changing your passwords and more in our Help Center.

It's worth noting that, so far, we've discovered that the list of alleged accounts and passwords found on Pastebin consists of more than 20,000 duplicates, many spam accounts that have already been suspended and many login credentials that do not appear to be linked (that is, the password and username are not actually associated with each other).

The Verge
Log In Sign Up

Log In Sign Up

Please choose a new Verge username and password

As part of the new Verge launch, prior users will need to choose a permanent username, along with a new password.

Your username will be used to login to Verge going forward.

I already have a Vox Media account!

Verify Vox Media account

Please login to your Vox Media account. This account will be linked to your previously existing Eater account.

Please choose a new Verge username and password

As part of the new Verge launch, prior MT authors will need to choose a new username and password.

Your username will be used to login to Verge going forward.

Forgot password?

We'll email you a reset link.

If you signed up using a 3rd party account like Facebook or Twitter, please login with it instead.

Forgot password?

Try another email?

Almost done,

By becoming a registered user, you are also agreeing to our Terms and confirming that you have read our Privacy Policy.



Choose an available username to complete sign up.

In order to provide our users with a better overall experience, we ask for more information from Facebook when using it to login so that we can learn more about our audience and provide you with the best possible experience. We do not store specific user data and the sharing of it is not required to login with Facebook.