Twitter says it has suspended “a large network of fake accounts” and many others for abusing an API feature that let them match phone numbers to usernames
Twitter announced today that over the holidays it identified and shut down “a large network of fake accounts,” …
TechCrunchDevin Coldewey
Context & Ripple Effects
This is the third wave of a recurring pattern at Twitter: after suspending 142K apps responsible for 130M low-quality tweets via API enforcement in 2018, and running suspensions at a reported pace of over 1M accounts per day that same year, the company is again closing an API surface — this time one that let abusers match phone numbers to usernames, effectively de-anonymizing users. The holidays-timing disclosure suggests the abuse ran undetected through a period when enforcement attention was elsewhere.
The mechanism matters more than the volume: unlike spam networks that inflate follower counts, a phone-to-username match exposes real-world identities behind pseudonymous accounts, which is why Twitter treated it as grounds for a large-scale purge rather than routine cleanup.
First-order effects
The fake-account network and its affiliates lose their accounts outright, and Twitter must restrict or gate the phone-number-matching API endpoint that enabled the abuse, changing what legitimate developers can query.
Users whose numbers were matched face exposure of pseudonymous identities — the direct harm Twitter's disclosure implicitly acknowledges.
Second-order effects
Twitter's developer ecosystem absorbs another round of tightened API access, following the 2018 crackdown that killed 142K apps; third-party tools touching user-identity data now carry higher compliance risk and narrower scope.
Each disclosed API-abuse episode feeds advertiser and regulator skepticism about platform integrity — the same disinformation-fighting posture that drove the million-a-day suspension era now extends to identity-data plumbing, not just content.
Third-order effects
If platforms keep discovering that open identity-linked APIs enable de-anonymization at scale, the structural endpoint is treating personhood as something to be verified rather than inferred — pushing the industry toward stricter proof-of-personhood mechanisms and away from free identity-data access.
Recurring bot purges become a permanent operating cost baked into platform economics, with API openness traded away incrementally each time an abuse vector surfaces.
The trend: Social platforms are progressively walling off identity-linked data and shifting toward explicit person-verification, as every open API surface becomes an attack vector for coordinated fake-account operations.
We recently discovered an issue that allowed bad actors to match a specific phone number with the corresponding accounts on Twitter. We quickly corrected this issue and are sorry this happened. You can learn more about our investigation here: https://privacy.twitter.com/ ...
BREAKING: Twitter says a suspected state-sponsored actor used its API to match usernames to phone numbers - Attack took place on December 24, 2019 - Twitter said attack came from IPs in Iran, Israel, and Malaysia https://www.zdnet.com/... https://twitter.com/...
Twitter has really hashed up this disclosure. No wonder initial reports got this wrong. Twitter still needs to explain its attribution here. My @TechCrunch colleague, who isn't on Twitter (lucky him) has an accurate understanding of what went on. https://techcrunch.com/...
Twitter's & @jack's stunning failure to protect users' privacy is a matter of life & death for human rights advocates & journalists around the world. Twitter must urgently notify those compromised by these attacks—their safety & freedom could be at immediate risk. https://twitter…
could mean many Iranian users were at risk: twitter says some ppl were using large network of fake acc's to exploit its API & match usernames to phone numbers- high vol of such requests coming from addresses in Iran, Israel, & Malaysia, w/ possible ties to state-sponsored actors.…
I don't understand. The attack worked only against users who configured accounts to be matched to their phone number. That means these users chose to allow people to match phone numbers to accounts, right? If so, how is this an attack? What am I missing? https://twitter.com/...
Twitter data breach. Only potentially impacted when you have the option “let people who have your phone number find you...” enabled and your phone number set in Twitter. Remove your phone number, better safe than sorry! it's not needed anymore for 2FA anyway #Infosec #GDPR https:…
“... we observed a particularly high volume of requests coming from individual IP addresses located within Iran, Israel, and Malaysia. ...” https://twitter.com/...
😐 There now probably exists somewhere a list of phone numbers and account usernames. This puts 2FA security at risk for all those accounts. Make sure your 2FA is secured via third party authorization app, not via text message https://twitter.com/...
A little surprised it took more than a month to disclose this but if you read my story back in December, you know this already. https://techcrunch.com/... https://twitter.com/...