A bug Twitter downplayed in 2012 resurfaces as researchers hijack celebrity accounts to send tweets by using a UK mobile phone number tied to an account
Twitter is claiming to have resolved a bug that allowed a group of London-based security researchers to post unauthorized tweets …
Context & Ripple Effects
This 2018 incident is the first entry in what became a recurring vulnerability class for Twitter: anything that lets an outsider map a phone number to a specific account. London-based researchers showed a UK mobile number alone was enough to post tweets from celebrity accounts, exploiting a flaw Twitter had downplayed since 2012 before claiming it was resolved.
The pattern held after this story: a researcher later matched 17M phone numbers to Twitter user accounts through the Android app before Twitter blocked him, and by 2022 Twitter confirmed a now-patched bug behind a threat actor's offer to sell 5.4M records linking phone numbers and emails to users. The 2018 hijack reads less like a one-off than the opening data point.
First-order effects
- Celebrity and high-profile accounts were directly exposed: anyone who could tie a UK mobile number to an account could publish unauthorized tweets under that account's name until Twitter patched the flaw.
- Twitter's immediate move was to declare the vulnerability resolved, containing the reputational damage from a bug its own engineers had previously minimized in 2012.
Second-order effects
- Security researchers kept probing the same attack surface — the Android-app flaw that surfaced phone-number matches in 2019 shows the fix did not close the broader class, forcing repeated patch cycles.
- Once lookup flaws proved reliable, the incentive shifted from demonstration to monetization, culminating in the 2021-2022 attempt to sell millions of phone-number-to-account records.
Third-order effects
- If the pattern holds, phone numbers function as a persistent weak link in platform identity systems: every feature that associates a number with an account creates a de facto directory that researchers and criminals can enumerate.
- For platforms built on pseudonymity, repeated enumeration bugs push toward decoupling contact information from discoverable identity — a structural change in how account recovery and privacy controls are designed.
The trend: Phone-number-to-account mapping has been Twitter's most repeatedly exploited attack surface, turning each lookup or recovery feature into a fresh enumeration risk.