Twitter has acknowledged that the July data breach, which led to the sale of millions of user accounts, was caused by an exploited zero-day vulnerability.
According to Restore Privacy, in late July, a user going by the handle “devil” posted to Breached Forums stating they possessed 5.4 million Twitter user accounts and would sell the information for US$30,000.
Twitter has now admitted that the account information was stolen by using a zero-day vulnerability that it initially discovered in January 2022.
A hacker with access to the bug may utilise phone numbers to determine whether a user account was present.
The issue allowed an attacker to find a Twitter account by phone number or email address, “even if the user has disallowed this in the privacy options,” as “zhirinovskiy” explained in their Hacker One report.
The Twitter Android client’s authorization process, notably the step where it checks for duplicate Twitter accounts, is to blame for the problem.
For the report, Zhirinovskiy received US$5040 (A$7273).
The problem “enabled someone to insert a phone number or email address into the log-in flow in an attempt to learn if that information was related to an existing Twitter account, and if so, which specific account,” according to Twitter’s article, which was validated by the company.
The same may be done with emails, according to Twitter’s post.
As soon as we were made aware of this, we looked into it and remedied it, according to Twitter.
“In July 2022, we discovered via a press report that someone may have taken advantage of this and was attempting to sell the data they had gathered.
“We established that a bad actor had exploited the problem before it was patched after evaluating a sample of the available data for sale.”


