Skip to main content

Twitter says state-backed attackers may have nabbed phone numbers

Twitter has revealed more details about a security incident that allowed attackers to discover phone numbers attached to numerous accounts on its platform.

The process involved exploiting a feature, which, when used in the intended way, lets new sign-ups find friends who are already on Twitter by inputting their phone number. The feature works for those who have enabled the “Let people who have your phone number find you on Twitter” option and who have a phone number associated with their Twitter account.

The company said that during a recent investigation, it discovered and subsequently shut down a large network of fake accounts that may have been attempting to match a huge number of generated phone numbers to Twitter accounts.

It said it realized something was wrong when it observed “a particularly high volume” of attempts coming from individual IP addresses located within Iran, Israel, and Malaysia, adding, “It is possible that some of these IP addresses may have ties to state-sponsored actors.” Speaking to Reuters, a Twitter spokesperson said its team had particular concerns about Iran as the attackers seemed to have had unrestricted access to the social media platform despite it being banned in the country.

Twitter said it has now made changes to its system to prevent similar attacks in the future, and also shut down the accounts that it believed were attempting to exploit the flaw.

Background

The issue was first exposed in December 2019 by London-based security researcher Ibrahim Balic. It seems that it was Balic’s discovery that prompted Twitter’s investigation, which led to the suspected state-backed attackers. Balic showed that he was able to match 17 million phone numbers to Twitter accounts by uploading more than 2 billion random numbers to the service. The exercise enabled him to discover the phone numbers of various high-profile Twitter users, among them politicians and officials.

The incident is the latest in a series of security mishaps to hit Twitter. Late last year, for example, the company revealed it had patched a vulnerability in its Android app that could have let malicious actors view information of private accounts and take over profiles, and even send direct messages and tweets on the target account’s behalf. Another error saw the platform reveal the tweets of protected accounts.

Announcing details of security incidents is part of Twitter’s recently launched effort to be more transparent with its community of around 330 million people globally.

Editors' Recommendations

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Apple may face ‘severe’ iPhone 15 shortage over production issue, report says
The Apple logo on the iPhone 14 Pro Max.

Hoping to get your hands on an iPhone 15 Pro or iPhone 15 Pro Max when the new phones come out in the fall? Well, you may be in for a wait.

Apple is experiencing production issues caused by a new manufacturing process designed to significantly reduce the size of the bezel around the display, according to a report from The Information on Thursday.

Read more
This phone may have already beat the Galaxy Z Flip 5 in a big way
A leaked render of the Oppo Find N3 Flip that shows the phone unfolded with three cameras on its front cover.

Foldable phones are getting exponentially better with each new iteration, and a new smartphone might already be outdoing the Galaxy Z Flip 5 before it even hits store shelves. According to a new leaked render, the Oppo Find N3 Flip will be outfitted with a triple-camera setup — a major step up from the dual-camera arrays that flip smartphones have been rocking for the past several years.

As shared by 91Mobiles, the Oppo Find N3 Flip will feature three cameras on its cover: a 50MP main lens, an 8MP ultrawide lens, and a 32MP telephoto lens. If the information is true, which it seems like it might be, then the Find N3 Flip will be breaking new ground for photographers who are looking to enjoy the benefits of foldable devices.

Read more
Elon Musk says he’s appointed a new Twitter CEO
A digital image of Elon Musk in front of a stylized background with the Twitter logo repeating.

Twitter owner Elon Musk has found someone to replace him as the company’s CEO, but he hasn't revealed who it is.

Musk tweeted on Thursday that the new CEO will step into the role at some point over the next six weeks.

Read more