Twitter Says State-Backed Actors May Have Accessed Users' Phone Numbers

Twitter said it had identified a "high volume of requests" to use the feature coming from IP addresses in Iran, Israel and Malaysia.

Advertisement
By Reuters | Updated: 4 February 2020 10:45 IST
Highlights
  • A security researcher unearthed a flaw in "contacts upload" feature
  • Twitter suspected a possible connection to state-backed actors
  • Twitter couldn't identify all of the accounts that may have been impacted

Twitter is not sending individual notifications to users whose phone numbers were accessed

Twitter said on Monday that it had discovered attempts by possible state actors to access the phone numbers associated with user accounts, after a security researcher unearthed a flaw in the company's "contacts upload" feature.

In a statement published on its privacy blog, Twitter said it had identified a "high volume of requests" to use the feature coming from IP addresses in Iran, Israel, and Malaysia. It said, without elaborating, that "some of these IP addresses may have ties to state-sponsored actors."

Advertisement

A company spokeswoman declined to say how many user phone numbers had been exposed, saying Twitter was unable to identify all of the accounts that may have been impacted.

She said Twitter suspected a possible connection to state-backed actors because the attackers in Iran appeared to have had unrestricted access to Twitter, even though the network is banned there.

Advertisement

Tech publication TechCrunch reported on December 24 that a security researcher, Ibrahim Balic, had managed to match 17 million phone numbers to specific Twitter user accounts by exploiting a flaw in the contacts feature of its Android app. TechCrunch said it was able to identify a senior Israeli politician by matching a phone number through the tool.

The feature, which allows people with a user's phone number to find and connect with that user on Twitter, is off by default for users in the European Union where stringent privacy rules are in place. It is switched on by default for all other users globally, the spokeswoman said.

Advertisement

Twitter said in its statement that it has changed the feature so it no longer reveals specific account names in response to requests. It has also suspended any accounts believed to have been abusing the tool.

However, the company is not sending individual notifications to users whose phone numbers were accessed in the data leak, which information security experts consider a best practice.

Advertisement

© Thomson Reuters 2020

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Twitter
Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Find X9 Ultra With 200-Megapixel Periscope Camera Launched Globally
  2. Vivo X300 FE Roundup: Expected Price in India, Specifications
  3. Motorola Edge 70 Fusion Review
  4. Poco M8s 5G Debuts Globally With 7,000mAh Battery: See Price, Features
  5. Xiaomi TV S Mini LED 75 (2026) Review
  6. Oppo Enco Clip 2 With Open-Ear Design, Launched Alongside Oppo Watch X3 Mini
  1. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  2. Oppo Enco Clip 2 With Open-Ear Design, Up to 40 Hours Total Battery Life Launched Alongside Oppo Watch X3 Mini
  3. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
  4. OCBC Partners Lion Global Investors and DigiFT to Launch Tokenised Gold Fund With GOLDX Token
  5. Oppo Pad 5 Pro Launched With 13,380mAh Battery, Snapdragon 8 Elite Gen 5 SoC Alongside Oppo Pad Mini: Price, Features
  6. Redmi K90 Max Launched With Dimensity 9500 SoC, 8,550mAh Battery and Active Cooling Fan: Price, Specifications
  7. Oppo Find X9 Ultra Launched With Snapdragon 8 Elite Gen 5 SoC, 200-Megapixel Periscope Camera: Price, Specifications
  8. Oppo Find X9s Pro Launched With 200-Megapixel Cameras, 7,025mAh Battery: Price, Specifications
  9. OnePlus Ace 6 Ultra Geekbench Listing Reveals MediaTek Dimensity 9500 Chip, 16GB RAM
  10. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.