Twitter suspends ‘large network’ of fake accounts used to match phone numbers to users


Twitter announced today that over the holidays it identified and shut down “a large network of fake accounts,” as well as many others “located in a wide range of countries,” collectively abusing a feature that let them match phone numbers to user accounts.
TechCrunch previously reported this same issue on December 24, which is also the day Twitter says that it “became aware” that the abuse was taking place. Security researcher Ibrahim Balic found that a bug in Twitter’s Android app let him submit millions of phone numbers through an official API, which returned any associated user account.
We recently discovered an issue that allowed bad actors to match a specific phone number with the corresponding accounts on Twitter. We quickly corrected this issue and are sorry this happened. You can learn more about our investigation here: https://t.co/Z6Q4geQ8jo
— Twitter Support (@TwitterSupport) February 3, 2020
The feature is intended, if you have enabled it, to let friends who have your number look up your Twitter handle. But obviously submitting millions of numbers goes “beyond its intended use case.”
If you had turned this feature off, you weren’t affected by this bug. Fortunately for users in the E.U. this was opt-in there. But for the rest of the world it’s opt-out — so if you had a phone number associated with your account, you may have been affected.
Furthermore, the phone numbers include those provided for purposes of two-factor authentication, so those outside the E.U. may have been vulnerable to this exploit without realizing it.
It seems that after Twitter was alerted to the issue and shut down the original network (presumably Balic’s), its investigators identified many more accounts that were exploiting this flaw, though a representative declined to provide a number or estimate.
“We observed a particularly high volume of requests coming from individual IP addresses located within Iran, Israel, and Malaysia,” wrote the company in a security bulletin. “It is possible that some of these IP addresses may have ties to state-sponsored actors,” the post continued.
This suspicion was justified by the observation of unrestricted access to Twitter from the IPs in Iran, where the platform is blocked from general access — suggesting government involvement. Belic, when contacted by TechCrunch, said that his work was not state-sponsored in any way.
Any account suspected of abusing the feature was suspended, and the API itself has been modified to prevent any further exploitation of this type. I’ve asked the company how many accounts were suspended and will update this post if I hear back.
Twitter has had numerous incidents where it exposed or leaked user data over the last year. In addition to sharing rather too much data with its ad partners, the company admitted it used phone numbers used for two-factor authentication to serve targeted ads.
Twitter announced today that over the holidays it identified and shut down “a large network of fake accounts,” as well as many others “located in a wide range of countries,” collectively abusing a feature that let them match phone numbers to user accounts. TechCrunch previously reported this same issue on…
Recent Posts
- Reddit is experiencing outages again
- OpenAI confirms 400 million weekly ChatGPT users – here’s 5 great ways to use the world’s most popular AI chatbot
- Elon Musk’s AI said he and Trump deserve the death penalty
- Grok resets the AI race
- The GSA is shutting down its EV chargers, calling them ‘not mission critical’
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010