Researcher says he was able to match 17M phone numbers to Twitter user accounts by exploiting a flaw in Twitter's Android app, before Twitter blocked his effort
Context & Ripple Effects
This is the third time in roughly a year that Twitter's phone-number plumbing has surfaced as an attack surface. In late 2018, researchers hijacked celebrity accounts by exploiting a UK mobile number tied to accounts — a bug Twitter had downplayed since 2012 (researchers hijacked celebrity accounts via a tied UK number). Now Zack Whittaker reports a researcher used a flaw in Twitter's Android app to match 17 million phone numbers to user profiles at scale, until Twitter blocked the effort.
The pattern matters because de-anonymization at this scale converts pseudonymous accounts into named identities — and the corpus shows it wasn't a one-off: by August 2022, Twitter confirmed a now-patched bug was exploited to link phone numbers and emails to accounts, with a threat actor offering 5.4M records for sale (Twitter's 2022 confirmation of the scraped-data sale).
First-order effects
- Twitter faces immediate exposure on its Android app, where the flaw lived, and must explain why blocking the researcher — rather than preventing the matching — was the effective fix for 17 million exposed mappings.
- Users whose numbers were matched lose practical anonymity: anyone holding the dataset can tie a phone number to a handle, affecting journalists, activists, and ordinary users alike.
Second-order effects
- Security researchers now have a documented playbook — contact-discovery endpoints abused as lookup oracles — which the 2022 incident showing 5.4M records offered for sale suggests was reused by malicious actors, not just ethical testers.
- Advertisers and regulators evaluating platform trustworthiness get fresh evidence that identity data on the platform leaks faster than it is protected, pressuring Twitter's data-handling disclosures.
Third-order effects
- If contact-graph abuse keeps recurring across years (2012, 2018, 2019, 2021-22), phone-number-based account recovery and discovery become a structural liability regulators may treat as a systemic design flaw rather than isolated bugs.
- Pseudonymity on large social platforms erodes as a default expectation, pushing users toward separate identity layers and pushing platforms toward minimizing stored contact data.
The trend: Social platforms' phone-number infrastructure is proving a recurring de-anonymization vector, with each disclosed scrape normalizing bulk identity-mapping of supposedly pseudonymous accounts.