I spent the vast majority of my day confirming the dumped usernames and passwords from WHO, Gates Foundation and NIH are from old, dated breaches of other companies. Someone went through all this trouble to pull their credentials off dumps from other hacks (1/3)
The credentials spread from 4chan to Pastebin to Twitter to far-right channels on Telegram, and were blasted to my colleagues and I at the NYT and apparently other outlets. Harassment and 'going viral' is the goal. Please let's not give these more attention than they're due. 2/3
Many thanks to @SteveD3 and others for helping me confirm as much today. As for the PR folks who tried to spin this to get press for your clients today... maybe vet these yourself first. 3/3
You can follow @nicoleperlroth.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled: