Twitter Shuts Down Vast Fake Account Network Exploiting Phone Number Bug
Twitter suspends a massive network of fake accounts that abuse a system flaw to match millions of phone numbers to specific user profiles. The platform detects suspicious activity originating from IP addresses in Iran, Israel, and Malaysia.
Twitter shuts down a large network of fake accounts that exploit a feature designed to match phone numbers to specific user profiles. A security researcher discovers a bug in Twitter's Android app that allows anyone to submit millions of phone numbers through an official API to reveal associated accounts. Twitter corrects the issue after it becomes aware of the abuse on December 24.
This flaw affects users outside the European Union who link a phone number to their accounts, including those who provide numbers specifically for two-factor authentication. While the feature lets friends find user handles by phone number, malicious actors use it far beyond its intended purpose to harvest vast amounts of user data.
The company's investigation reveals a high volume of requests coming from IP addresses in Iran, Israel, and Malaysia. Twitter suspects possible state-sponsored involvement due to unrestricted platform access originating from Iran, where the social network is officially blocked for the general public.