/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A bug Twitter downplayed in 2012 resurfaces as researchers hijack celebrity accounts to send tweets by using a UK mobile phone number tied to an account

Twitter is claiming to have resolved a bug that allowed a group of London-based security researchers to post unauthorized tweets …

Gizmodo Dell Cameron

Context & Ripple Effects

This 2018 incident is the first entry in what became a recurring vulnerability class for Twitter: anything that lets an outsider map a phone number to a specific account. London-based researchers showed a UK mobile number alone was enough to post tweets from celebrity accounts, exploiting a flaw Twitter had downplayed since 2012 before claiming it was resolved.

The pattern held after this story: a researcher later matched 17M phone numbers to Twitter user accounts through the Android app before Twitter blocked him, and by 2022 Twitter confirmed a now-patched bug behind a threat actor's offer to sell 5.4M records linking phone numbers and emails to users. The 2018 hijack reads less like a one-off than the opening data point.

First-order effects

  • Celebrity and high-profile accounts were directly exposed: anyone who could tie a UK mobile number to an account could publish unauthorized tweets under that account's name until Twitter patched the flaw.
  • Twitter's immediate move was to declare the vulnerability resolved, containing the reputational damage from a bug its own engineers had previously minimized in 2012.

Second-order effects

  • Security researchers kept probing the same attack surface — the Android-app flaw that surfaced phone-number matches in 2019 shows the fix did not close the broader class, forcing repeated patch cycles.
  • Once lookup flaws proved reliable, the incentive shifted from demonstration to monetization, culminating in the 2021-2022 attempt to sell millions of phone-number-to-account records.

Third-order effects

  • If the pattern holds, phone numbers function as a persistent weak link in platform identity systems: every feature that associates a number with an account creates a de facto directory that researchers and criminals can enumerate.
  • For platforms built on pseudonymity, repeated enumeration bugs push toward decoupling contact information from discoverable identity — a structural change in how account recovery and privacy controls are designed.

The trend: Phone-number-to-account mapping has been Twitter's most repeatedly exploited attack surface, turning each lookup or recovery feature into a fresh enumeration risk.