Twitter says state-backed actors may have accessed users' phone numbers

FILE PHOTO: The Twitter logo and binary cyber codes are seen in this illustration taken November 26, 2019. REUTERS/Dado Ruvic/Illustration/File Photo

SAN FRANCISCO (Reuters) – Twitter said on Monday that it had discovered attempts by possible state actors to access the phone numbers associated with user accounts, after a security researcher unearthed a flaw in the company’s “contacts upload” feature.

In a statement published on its privacy blog, Twitter said it had identified a “high volume of requests” to use the feature coming from IP addresses in Iran, Israel and Malaysia. It said, without elaborating, that “some of these IP addresses may have ties to state-sponsored actors.”

A company spokeswoman declined to say how many user phone numbers had been exposed, saying Twitter was unable to identify all of the accounts that may have been impacted.

She said Twitter suspected a possible connection to state-backed actors because the attackers in Iran appeared to have had unrestricted access to Twitter, even though the network is banned there.

vCard QR Code

vCard.red is a free platform for creating a mobile-friendly digital business cards. You can easily create a vCard and generate a QR code for it, allowing others to scan and save your contact details instantly.

The platform allows you to display contact information, social media links, services, and products all in one shareable link. Optional features include appointment scheduling, WhatsApp-based storefronts, media galleries, and custom design options.

Tech publication TechCrunch reported here on Dec. 24 that a security researcher, Ibrahim Balic, had managed to match 17 million phone numbers to specific Twitter user accounts by exploiting a flaw in the contacts feature of its Android app. TechCrunch said it was able to identify a senior Israeli politician by matching a phone number through the tool.

The feature, which allows people with a user’s phone number to find and connect with that user on Twitter, is off by default for users in the European Union where stringent privacy rules are in place. It is switched on by default for all other users globally, the spokeswoman said.

Twitter said in its statement that it has changed the feature so it no longer reveals specific account names in response to requests. It has also suspended any accounts believed to have been abusing the tool.

However, the company is not sending individual notifications to users whose phone numbers were accessed in the data leak, which information security experts consider a best practice.

Reporting by Katie Paul; Editing by Leslie Adler

Our Standards:The Thomson Reuters Trust Principles.
source: reuters.com


🕐 Top News in the Last Hour By Importance Score

# Title 📊 i-Score
1 This is what the Pope told me when we met… and it has stayed with me 🟢 85 / 100
2 Netanyahu demanded loyalty before trying to fire me, Shin Bet chief claims 🔴 75 / 100
3 Nigeria reduces electricity subsidies by 35% following tariff hike for heavy users 🔴 72 / 100
4 Pope Francis' lying in state plans: How pontiff's body will be dressed and where his coffin will be held for tens of thousands of Catholics to pay their respects 🔴 72 / 100
5 Luis Arraez ‘out of the woods’ after scary collision 🔴 65 / 100
6 Suspect identified in 53-year-old cold case killing of Indiana woman 🔴 65 / 100
7 Conclave plot, cast and ways to watch hit political thriller at home 🔵 50 / 100
8 A green comet likely is breaking apart and won't be visible to the naked eye 🔵 45 / 100
9 Lost Records Sets A Sequel Up Much Better Than Life Is Strange: Double Exposure 🔵 45 / 100
10 Basketball's biggest rising star Cooper Flagg, 18, reveals NBA Draft decision 🔵 35 / 100

View More Top News ➡️