I-hacker engaziwayo okanye iqela le-hacker lifake i-database ye-intanethi equkethe iidilesi ze-imeyile kunye neenombolo zefowuni ezinxulumene ne-akhawunti ye-Twitter ye-5.4 yezigidi. Umhlaseli ukwazile ukubuyisela idatha nge-bug esele ilungisiwe.
Uvimba weenkcukacha unikezelwe kwiiForam zoKwaphula umthetho kwaye wafunyanwa nguBuyisela uBucala. Abahlaseli bafuna "ubuncinci i-$ 30,000" kwisiseko sedatha. I-database ayinamagama ayimfihlo, kodwa iqulethe iidilesi ze-imeyile okanye iinombolo zefowuni okanye zombini i-5,485,636 abasebenzisi be-Twitter bebonke. Umhlaseli uthi ukuphulwa kwedatha kuqulethe iiakhawunti zabantu abadumileyo kunye neenkampani. Ukubuyisela uBucala kuye kwakwazi ukufumanisa ukuba ukuvuza kuyinyani, kodwa kungekhona ukuba ibango lokuba amagama adumileyo ayekuyo.
Umhlaseli ufikelele kubuthathaka ngobungozi obaziwayo obuye balungiswa. Ukuba sesichengeni kwaboniswa nge-1 kaJanuwari kwi-bug bounty platform HackerOne ngumphandi wokhuseleko. Kwakuyi-bug kumthengi we-Android owayefuna umhlaseli enze isicelo se-POST kwi-API yokungena kwi-Twitter. Umphandi wokhuseleko uchaza umba ngokubanzi kwiHackerOne. I-Twitter yathatha ubuthathaka kwaye yalungisa ngoJanuwari 13. Iinkcukacha zapapashwa ngoFebruwari 11, kwaye umphandi wanikwa umvuzo we-$ 5040. Akwaziwa ukuba umhlaseli ngoku onikezela ngesiseko sedatha walufumana njani ulwazi lokuqhuba olu hack.