Twitter confirms that a now-patched bug was used to link phone numbers and emails to user accounts; a threat actor offered to sell 5.4M records in December 2021
The confirmed exposure adds a data-linkage failure to that history: even after the bug was patched, records associated with it had reportedly been offered for sale. That leaves Twitter managing the consequences of data already outside its systems.
First-order effects
Twitter must address users whose email addresses or phone numbers may have been connected to their accounts through the flaw, while the patch only stops further exploitation of that route.
The threat actor's offered 5.4M-record dataset turns an account-discovery weakness into an exposure that can be reused independently of Twitter's current product controls.
Second-order effects
People whose contact details appear in the dataset face more targeted account-identification and impersonation risk, because the records link identifiers that are often kept separate.
Twitter's prior use of security contact data for advertising makes clearer separation of security, discovery, and advertising uses more important to restoring confidence in its contact-data handling.
Third-order effects
Repeated failures involving phone numbers and email addresses push social platforms toward treating identifier-linking protections as a core part of consent architecture, not merely an account-recovery feature.
As leaked identifier datasets persist, a platform's security posture is increasingly judged by how long previously exposed account mappings remain useful to attackers.
The trend: Social platforms are facing a broader shift toward stricter controls over the identifiers users provide for security, discovery, and advertising.
Twitter compromised: “In July 2022, we learned through a press report that someone had potentially leveraged this and was offering to sell the information they had compiled.” https://privacy.twitter.com/ ...
“[W]e encourage everyone who uses Twitter to enable 2-factor authentication using authentication apps or hardware security keys to protect your account from unauthorized logins.” https://twitter.com/...
Twitter discloses a security breach -someone used a vulnerability to discover the emails and phone numbers of Twitter accounts -data of said accounts was later sold online -vulnerability was also reported to Twitter via its bug bounty program https://privacy.twitter.com/ ... http…
👀"We want to let you know about a vulnerability that allowed someone to enter a phone number or email address into the log-in flow in the attempt to learn if that information was tied to an existing Twitter account, and if so, which specific account." https://privacy.twitter.com/…
“We can confirm the impact was global,” a Twitter spokesperson said in an email. “We cannot determine exactly how many accounts were impacted or the location of the account holders.” A set being sold by a hacker online shows it could be 5 million users. https://www.cyberscoop.com…
“If the Iranian regime can get a copy of this data and then find their target, it doesn't matter if the user deletes the account right now because the user will be identified via mobile number or email,” @AminSabeti told CyberScoop. https://www.cyberscoop.com/...