/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Twitter fixes flaw in support form that leaked users' phone number country codes and other info, after noticing excessive queries from Chinese and Saudi IPs

which even some of the best in the industry struggle with. http://techcrunch.com/... Josh Constine / @joshconstine : Twitter fails the apology test here by refusing to acknowledge how the leak could harm people or what it's doing to prevent future problems like this. Tech giants say sorry but don't change. http://techcrunch.com/... Josh Constine / @joshconstine : Twitter wouldn't tell TechCrunch how many accounts were impacted as it says it's still investigating, but confirms it has disclosed the issue to the FTC & EU regulators http://twitter.com/...

TechCrunch Josh Constine

Context & Ripple Effects

This December 2018 disclosure is an early entry in what becomes a running file on Twitter's data handling: within months the company would report inadvertently sharing iOS location data with an unnamed ad partner, then two more ad-targeting bugs in August 2019, then security-purpose emails and phone numbers repurposed for targeting that October. What distinguishes this incident is the detection vector — excessive queries from Chinese and Saudi IPs — meaning the flaw was found because someone was actively probing it.

That probing detail matters because the same flaw class resurfaces: in 2022 Twitter confirmed a patched bug had been used to link phone numbers and emails to accounts, with a threat actor offering 5.4M records for sale traced back to late 2021. The company's refusal here to say how many accounts were affected, while disclosing to the FTC and EU regulators, sets the disclosure posture its critics — including TechCrunch's Josh Constine — flag as failing the apology test.

First-order effects

  • Users whose phone numbers were entered into the support form had their country codes and associated information exposed to whoever was querying it from those Chinese and Saudi IP addresses, while Twitter declines to quantify the blast radius pending investigation.
  • The FTC and EU regulators now hold formal disclosures on the incident, putting Twitter's data practices on the record with both US and European authorities at once.

Second-order effects

  • Constine's 'apology test' critique — no acknowledgment of harm, no prevention plan — raises the reputational cost of Twitter's disclose-minimally pattern, pressure that compounds with each subsequent leak in the 2019–2022 sequence.
  • State-adjacent IP activity against a consumer support endpoint signals to other platforms that these low-glamour forms are attack surface, forcing broader scrutiny of internal tooling rather than just public-facing APIs.

Third-order effects

  • If the pattern holds — accidental exposure, thin disclosure, then the same data class exploited at scale as in the 2022 record sale — regulators move from accepting self-reports to demanding impact quantification and breach-prevention evidence, tightening access-control regulation around user-supplied contact data.
  • Security data collected for account protection becomes a liability ledger: every phone number a platform stores for verification is a future breach inventory, pushing the industry toward minimizing what it retains rather than only how it guards it.

The trend: Platform data incidents are shifting from isolated accidental leaks to a recurring cycle where probed flaws become monetized exploits, steadily raising the regulatory price of opaque disclosure.