Lucian Constantin
CSO Senior Writer

Hackers breach social media accounts of Mark Zuckerberg and other celebrities

news
Jun 6, 20162 mins

The compromises might be the result of recent data breaches from other websites that exposed user passwords

Mark Zuckerberg (1)
Credit: Martyn Williams/IDGNS

Over the weekend hackers managed to access Facebook founder Mark Zuckerberg’s Twitter and Pinterest accounts, as well as the social media accounts of other celebrities.

Someone posted to Zuckerberg’s Twitter feed on Sunday, claiming to have found his password in account information leaked from LinkedIn.

A group calling itself the OurMine Team took credit for breaking into Zuckerberg’s Twitter, Pinterest and Instagram accounts, but there’s no evidence that the Instagram account has been breached.

“You were in LinkedIn Database with password ‘dadada’,” read a message supposedly posted by hackers from Zuckerberg’s @finkd Twitter account. 

It’s worth noting that Zuckerberg or his representatives rarely use this account, the last tweet dating from Jan. 2012 and the previous one from Mar. 2009.

Facebook representatives did not immediately respond to a request for comment.

The Twitter accounts of founding Rolling Stones member Keith Richards, American comedy rock duo Tenacious D and late TV personality Ryan Dunn were also compromised.

If indeed the breaches were related to the recently leaked database of LinkedIn accounts that was stolen in 2012, they highlight why it’s important to use different passwords for different online accounts.

Websites can have different security levels for storing user passwords. As past breaches have shown, some websites store passwords in plain text, while some store hashes — cryptographic representations of those passwords.

In the case of LinkedIn, the company stored password hashes, but they were generated using an insecure function called SHA1, making most of them easily crackable.

Users are better off assuming that any website will be compromised at some point and that their password used on that website will be exposed. With that in mind, it’s best to limit the potential damage by using unique, complex passwords for each online account.

A password manager application can make dealing with multiple passwords easier and if a website offers two-factor authentication as an account security measure, it’s a good idea to use that too.

Lucian Constantin

Lucian Constantin writes about information security, privacy, and data protection for CSO. Before joining CSO in 2019, Lucian was a freelance writer for VICE Motherboard, Security Boulevard, Forbes, and The New Stack. Earlier in his career, he was an information security correspondent for the IDG News Service and Information security news editor for Softpedia.

Before he became a journalist, Lucian worked as a system and network administrator. He enjoys attending security conferences and delving into interesting research papers. He lives and works in Romania.

You can reach him at lucian_constantin@foundryco.com or @lconstantin on X. For encrypted email, his PGP key's fingerprint is: 7A66 4901 5CDA 844E 8C6D 04D5 2BB4 6332 FC52 6D42

More from this author