A vulnerability reported to Twitter through its bug bounty programme on 1 January 2022 allowed an unauthenticated request to resolve a phone number or email address to the account holding it. Reporting notes the lookup worked even where a user had disabled that association in privacy settings. Twitter fixed it on 13 January 2022.
On 21 July 2022 a seller listed data on 5.4 million accounts — email addresses and phone numbers — on a criminal forum, seeking $30,000. Twitter subsequently confirmed the breach. The data was reported released without charge on 27 November 2022.
Twelve Days Is Fast, And It Did Not Matter
A bug bounty report on 1 January and a fix on 13 January is a good response by any standard this corpus applies. It did not help the affected accounts.
Whatever had been harvested while the endpoint was open was already outside, and closing it changed nothing about that. We have recorded the same property at 25-0723 and 26-0714b, where stolen machine keys kept working after the patch, and at 22-1222, where an exfiltrated vault stayed attackable indefinitely. A fix stops accumulation; it does not recall.
The Setting Was The Whole Point
The users most harmed here are the ones who had gone into the settings and turned the association off — people running accounts under a name that is not the one on their phone contract.
For a pseudonymous account, a phone number is not contact data; it is the link between the pseudonym and the person. We have recorded the identical failure at 23-0808b, where the Electoral Commission breach included precisely those who had opted out of the public register. In both cases the control the system offered was real, and the breach went around it.
A Small Breach By The Usual Measures
No password, no payment detail, no identity document. Against 22-0922 or 22-1024 this looks minor, and the desk grades it SEV 3 accordingly.
Severity scored on data category is the wrong instrument for this one. For a user in a jurisdiction where their posting would be prosecuted, an email-to-account mapping is the most dangerous record in this corpus, and no scoring scheme the desk uses would show it. That limitation is recorded at 22-0118 and 23-0808, and we noted it here rather than adjusting the grade to compensate.
Compiled from contemporaneous reporting and Twitter’s confirmation, listed below. The researcher who reported the flaw is not named here. Whether all 5.4 million records were collected via this flaw is not established and is not asserted. Later and larger claims about Twitter datasets are separate and are not carried in this file. Graded high. Corrections: corrections@forensicpost.com.