Sadly it seems that someone has been out Phishing again and earlier I saw a tweet in my timeline from the Safety team at Twitter with regards to the attack and that accounts that they think may have been attacked have been sent a password reset

Some users are being targeted in phishing and/or brute force attacks; we have pushed out password resets to users possibly affected.
@safety
Safety

So if you do get an email from Twitter asking you to reset your password, first of all make sure that the link in the email does indeed go to Twitter and no where else and then go ahead with updating your Twitter.

Also: we'll NEVER auto-email you a new password; we use a reset process. Delete email attachments claiming to contain your PW; they don't.
@safety
Safety

Be safe and always make sure your email from Twitter is real, if Twitter think that you are at risk then you should have received one of these emails already or you will be getting one shortly, another good point to remember is try not to use website that ask for your Twitter password and only use sites that use the Twitter OAuth for your security when giving access to your Twitter account.

If you enjoyed reading this post, then please remember to post a comment, Subscribe to my RSS feed.


Protected by Copyscape Plagiarism Check Software

No related posts.

Written by Karen (965) Published Articles

Karen is founder of the Blazing Minds blog and avid blogger of all sorts of interesting and odd things. She is also the Apollo Rhyl Film Reviewer and also a keen music producer and founding member of the electronic music duo Remergence...

Link up with Karen at @BlazingMinds | | Facebook

 
 
35 Responses to “Another Twitter Phishing Attack, Password Resets Sent Out!”
  1. Andrew
    Twitter:
    says:

    Thanks for the heads-up!

    Have not yet received an email like this.

    Andrew
    Andrew recently posted..Sorry: I Am Not Replying To Comments (Temporarily)

  2. Tek3D
    Twitter:
    says:

    Oh, I received the same email from Twitter but I haven’t reset password yet. I have to do it right now :)
    Thanks.
    Tek3D recently posted..Interactive 3D Building Projection in Singapore

  3. Ileane
    Twitter:
    says:

    Karen, thanks for the news. This is the first I’ve heard of it but I will be sharing.
    Ileane recently posted..Buzz Besties – BuzzerList, Bit.ly Quick Tip, Blogger Bon Voyage

  4. Shiva
    Twitter:
    says:

    Thanks goodness I have not received any such kind of email. I will probably alert my friends about this
    Shiva recently posted..25 Best Books for WordPress Bloggers

  5. James
    Twitter:
    says:

    It’s scary how often the simplest attacks are the most effective… and it’s so easy to practice safe password behavior.
    James recently posted..Ring of Fire

  6. bbrian017
    Twitter:
    says:

    So far so good. I have not got any e-mail like this from my twitter account. Thanks for the heads up Karen
    bbrian017 recently posted..Are you being social the right way?

  7. Colleen
    Twitter:
    says:

    “…if you do get an email from Twitter asking you to reset your password, first of all make sure that the link in the email does indeed go to Twitter and no where else…”

    Why do they do this? It kills me when a platform uses live links to get a job done. Why not just tell the user to go jump on the internet and login to their account! Ebay was (and is) notorious for this. With all the phishing scams, you would think these folks would stop sending us emails with live links.
    Colleen recently posted..Utter Disappointment And The Classiest Acts That Followed, Armando Galarraga, Detroit Tigers, Jim Joyce

  8. My wife had this same alert for her Twitter account, but I didn’t get the notice from mine. When creating passwords for anything you should use the following rules:

    at least 8 characters long
    at least 1 digit
    at least 1 capital letter
    at least 1 special character (*,!,@,#,$,%…etc)
    this will ensure your password is strong and make it less likely to be cracked.

    Something like D!n0s@ur is really good, or *f0xYladies
    Dragon Blogger recently posted..SocialSpark Beginner Tips

  9. ashok says:

    I’m curious about the state of Twitter’s security generally. On the whole it seems to be rather safe and very functional. But I do wonder if its popularity has inherently made it a security risk. I also wonder if there’s something about Twitter’s own structure that gives it a bunch of users who want to do no good.
    ashok recently posted..Abraham Lincoln, “Letter to Ephraim D. and Phoebe Ellsworth”

  10. Metallman
    Twitter:
    says:

    Hey there Karen,

    Thanks for the heads up. I didn’t get this noticed and I didn’t hear any of my friends complain about getting it either so I’m hoping that it was a small group of people that were affected by this. Later!
    Metallman recently posted..Don’t Throw Away that Broken Camera/Camcorder

  11. plin
    Twitter:
    says:

    I did receive this email from Twitter which the first time I saw it I thought it was a phishing email in itself. As another commenter mentioned above, I didn’t expect them to send an email with a live link. Furthermore, I was quite surprised by the email as I haven’t logged into Twitter or any Twitter related services in weeks.

  12. chandan
    Twitter:
    says:

    Yesterday I have got mail from twitter for reset my password. I have got two time such mail. I changed my password at once.
    chandan recently posted..The benefit of number one rank at google

  13. John Sullivan
    Twitter:
    says:

    I got the email like someone mentioned I’m suspicious of those change your password emails but glad my account is ok a friend of mine who doesn’t tweet ads has some whacky ads tweeted from her acct a few times a day she changed her pw :) and it still tweets the ads :(
    Hope everyone has a great weekend
    Just went by that vote site seems the CSS is whacked :)
    he may be making changes again
    Thanks Karen for all your kindness

  14. Rakesh Solanki
    Twitter:
    says:

    Thank God, I have not got any e-mail like this from my twitter account. Thanks for the News Karen
    Rakesh Solanki recently posted..Schirmfoto – Screenshots Made Easy To Every Window

  15. john
    Twitter:
    says:

    I haven’t received any email. Maybe I am not that important for them :) )

  16. Typhoon
    Twitter:
    says:

    Phishing Attack doesn’t needs much resources..It just need a server, a fake looking page of the website and a script that will trace the username and password.

    I remember when I was into hacking, We created a phishing page for the popular site ‘Orkut’ just to see how many users fall into the trap..Then we just broadcasted a IM to our Yahoo Messenger list telling them that this is Orkut 2.0 and it’s available only for some time..

    The result were amazing..People really believed in it and submitted their original Orkut account information on our site..But we did just that for fun and none of the account were compromised as they were of our friends.

    It tells, how much people are aware about phishing and why so many people fall in it daily.

    PS. Recently, even I got a phishing mail for hacking my paypal..but since I’m aware of it, I replied back with bulls**t comments.. :D
    Typhoon recently posted..Top 7 Mistakes Made On Twitter By Bloggers And Internet Marketers

  17. Udegbunam Chukwudi from Make Money Online
    Twitter:
    says:

    I always thought twitter attacks/phishing were targeted @ big twitizens. I’ve never been hacked so far and hopefully wouldn’t be in the nearest future. On the other hand, my FB account has been hacked once by someone peddling “Colon Cleansers”. I had to reset my password to stop the messages and it worked ;-)

  18. John says:

    Why do people bother to do such things? What exactly do they stand to profit from such activity?
    John recently posted..Sat Nav’s at Shop GPS

  19.  
Leave a Reply


Comment Policy Important Please Read

Please be aware that all comments made are moderated and SPAM will not be tolerated, make sure you use your real name (NOT A WEBSITE NAME), you can also utilise (YOURNAME @ BLOG NAME), if we deem a comment to be SPAM then it will be edited or deleted! SPAMMERS are not welcome here! Comments without a Gravatar may also be deleted! Comments without a first name will NOT be approved!

Editors have the right to moderate or delete any comment they choose.

CommentLuv badge