Twitter fixes flaw in support form that leaked users' phone number country codes and other info, after noticing excessive queries from Chinese and Saudi IPs
which even some of the best in the industry struggle with. http://techcrunch.com/... Josh Constine / @joshconstine : Twitter fails the apology test here by refusing to acknowledge how the leak could harm people or what it's doing to prevent future problems like this. Tech giants say sorry but don't change. http://techcrunch.com/... Josh Constine / @joshconstine : Twitter wouldn't tell TechCrunch how many accounts were impacted as it says it's still investigating, but confirms it has disclosed the issue to the FTC & EU regulators http://twitter.com/...
Context & Ripple Effects
This December 2018 disclosure is an early entry in what becomes a running file on Twitter's data handling: within months the company would report inadvertently sharing iOS location data with an unnamed ad partner, then two more ad-targeting bugs in August 2019, then security-purpose emails and phone numbers repurposed for targeting that October. What distinguishes this incident is the detection vector — excessive queries from Chinese and Saudi IPs — meaning the flaw was found because someone was actively probing it.
That probing detail matters because the same flaw class resurfaces: in 2022 Twitter confirmed a patched bug had been used to link phone numbers and emails to accounts, with a threat actor offering 5.4M records for sale traced back to late 2021. The company's refusal here to say how many accounts were affected, while disclosing to the FTC and EU regulators, sets the disclosure posture its critics — including TechCrunch's Josh Constine — flag as failing the apology test.
First-order effects
- Users whose phone numbers were entered into the support form had their country codes and associated information exposed to whoever was querying it from those Chinese and Saudi IP addresses, while Twitter declines to quantify the blast radius pending investigation.
- The FTC and EU regulators now hold formal disclosures on the incident, putting Twitter's data practices on the record with both US and European authorities at once.
Second-order effects
- Constine's 'apology test' critique — no acknowledgment of harm, no prevention plan — raises the reputational cost of Twitter's disclose-minimally pattern, pressure that compounds with each subsequent leak in the 2019–2022 sequence.
- State-adjacent IP activity against a consumer support endpoint signals to other platforms that these low-glamour forms are attack surface, forcing broader scrutiny of internal tooling rather than just public-facing APIs.
Third-order effects
- If the pattern holds — accidental exposure, thin disclosure, then the same data class exploited at scale as in the 2022 record sale — regulators move from accepting self-reports to demanding impact quantification and breach-prevention evidence, tightening access-control regulation around user-supplied contact data.
- Security data collected for account protection becomes a liability ledger: every phone number a platform stores for verification is a future breach inventory, pushing the industry toward minimizing what it retains rather than only how it guards it.
The trend: Platform data incidents are shifting from isolated accidental leaks to a recurring cycle where probed flaws become monetized exploits, steadily raising the regulatory price of opaque disclosure.