Disclosed Jun 24, 201016 years agoSettled
Hackers gained admin control of Twitter twice in 2009; FTC security order
Between January and May 2009 hackers twice gained administrative control of Twitter, accessing non-public user information and private tweets and sending fake tweets. The FTC order, announced in June 2010 and finalized in March 2011, requires a security program with independent assessments for 10 years.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jun 24, 2010 |
| Discovered | 2009 |
| Attack | Hacking |
| Data exposed | Credentials and tokens, Messages, Other |
| Sector | Tech · US |
| Status | Settled |
| Lawsuit or fine | FTC consent order (finalized March 2011); no monetary penalty |
Sources
| Source | |
|---|---|
| FTC Accepts Final Settlement with Twitterftc.gov · Regulator | Regulator |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jun 24, 2010 |
Other breaches at Twitter
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Scraped emails and profiles of over 200 million Twitter users posted onlineJan 5, 20233 years agoScrapingUnverified | Jan 5, 20233 years ago | Scraping | Tech | Unverified | 212Macct |
| API flaw let attacker link emails and phone numbers to Twitter accountsAug 5, 20224 years agoHacking | Aug 5, 20224 years ago | Hacking | Media | Confirmed | 6.7Macct |
| Protected tweets bug notified late; Irish DPC fine of EUR 450,000Dec 15, 20205 years agoExposed data | Dec 15, 20205 years ago | Exposed data | Tech | Settled | Unknown |
| Phone spear phishing gives attackers internal tools, 130 accounts targetedJul 15, 20206 years agoPhishing | Jul 15, 20206 years ago | Phishing | Tech | Confirmed | 130 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.