Desk live·
ForensicPost
Breaches/Identity/File 22-0721

Twitter Flaw Exposed 5.4 Million Accounts Despite Privacy Settings

A flaw let anyone submit a phone number or email address and get back the Twitter account it belonged to — including for users who had explicitly turned that lookup off. It was fixed in twelve days, and the data taken in the meantime surfaced in July.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetTwitter
ActorUnattributed
S. Rosler11 min readConfidence: high2 sources reviewed

A vulnerability reported to Twitter through its bug bounty programme on 1 January 2022 allowed an unauthenticated request to resolve a phone number or email address to the account holding it. Reporting notes the lookup worked even where a user had disabled that association in privacy settings. Twitter fixed it on 13 January 2022.

On 21 July 2022 a seller listed data on 5.4 million accounts — email addresses and phone numbers — on a criminal forum, seeking $30,000. Twitter subsequently confirmed the breach. The data was reported released without charge on 27 November 2022.

Twelve Days Is Fast, And It Did Not Matter

A bug bounty report on 1 January and a fix on 13 January is a good response by any standard this corpus applies. It did not help the affected accounts.

Whatever had been harvested while the endpoint was open was already outside, and closing it changed nothing about that. We have recorded the same property at 25-0723 and 26-0714b, where stolen machine keys kept working after the patch, and at 22-1222, where an exfiltrated vault stayed attackable indefinitely. A fix stops accumulation; it does not recall.

The Setting Was The Whole Point

The users most harmed here are the ones who had gone into the settings and turned the association off — people running accounts under a name that is not the one on their phone contract.

For a pseudonymous account, a phone number is not contact data; it is the link between the pseudonym and the person. We have recorded the identical failure at 23-0808b, where the Electoral Commission breach included precisely those who had opted out of the public register. In both cases the control the system offered was real, and the breach went around it.

A Small Breach By The Usual Measures

No password, no payment detail, no identity document. Against 22-0922 or 22-1024 this looks minor, and the desk grades it SEV 3 accordingly.

Severity scored on data category is the wrong instrument for this one. For a user in a jurisdiction where their posting would be prosecuted, an email-to-account mapping is the most dangerous record in this corpus, and no scoring scheme the desk uses would show it. That limitation is recorded at 22-0118 and 23-0808, and we noted it here rather than adjusting the grade to compensate.

How we reported this

Compiled from contemporaneous reporting and Twitter’s confirmation, listed below. The researcher who reported the flaw is not named here. Whether all 5.4 million records were collected via this flaw is not established and is not asserted. Later and larger claims about Twitter datasets are separate and are not carried in this file. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Twitter fixes security bug that exposed at least 5.4 million accountsTechCrunch
  2. Twitter confirmed July 2022 data breach affecting 5.4M usersMalwarebytes
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary