Twitter has acknowledged that the July data breach, which led to the sale of millions of user accounts, was caused by an exploited zero-day vulnerability.
According to Restore Privacy, in late July, a user going by the handle “devil” posted to Breached Forums stating they possessed 5.4 million Twitter user accounts and would sell the information for US$30,000.
Twitter has now admitted that the account information was accessed by utilising a zero-day vulnerability that it initially discovered in January 2022.
A hacker with access to the bug may utilise phone numbers to determine whether a user account was present.
The issue allowed an attacker to find a Twitter account by phone number or email address, “even if the user has disallowed this in the privacy options,” as “zhirinovskiy” explained in their Hacker One report.
The Twitter Android client’s authorization process, notably the step where it checks for duplicate Twitter accounts, is to blame for the problem.
For the report, Zhirinovskiy received US$5040 (A$7273).
The flaw “enabled someone to insert a phone number or email address into the log-in flow in an attempt to ascertain if such information was related to an existing Twitter account, as stated by Twitter in its post.
As soon as we were made aware of this, we looked into it and remedied it, according to Twitter.
“In July 2022, we discovered via a press report that someone may have taken advantage of this and was attempting to sell the data they had gathered.
“We established that a bad actor had exploited the problem before it was patched after evaluating a sample of the available data for sale.”
Twitter defended publishing the message, saying that it was unable to get in touch with all the affected users, particularly those who were still using pseudonymous identities.


