'State actors' likely accessed users' phone numbers: Twitter

SPH Brightcove Video
Twitter said on Monday that it had discovered attempts by possible state-backed actors to access the phone numbers associated with user accounts, after a security researcher unearthed a flaw in the company's "contacts upload" feature.

SAN FRANCISCO • Twitter said it had discovered attempts by possible "state actors" to access phone numbers associated with user accounts, after a security researcher unearthed a flaw in the company's "contacts upload" feature.

In a statement published on its privacy blog on Monday, Twitter said it had identified a "high volume of requests" to use the feature coming from IP addresses in Iran, Israel and Malaysia. It said, without elaborating, that "some of these IP addresses may have ties to state-sponsored actors".

A spokesman declined to say how many user phone numbers had been exposed, saying Twitter was unable to identify all of the accounts possibly impacted.

She said Twitter suspected a possible connection to state-backed actors because the attackers in Iran appeared to have had unrestricted access to Twitter, even though the network is banned there.

TechCrunch reported on Dec 24 that a security researcher, Mr Ibrahim Balic, had managed to match 17 million phone numbers to specific Twitter user accounts by exploiting a flaw in the contacts feature of its Android app. The tech publication said it was able to identify a senior Israeli politician by matching a phone number through the tool.

The feature, which allows people with a user's phone number to find and connect with that user on Twitter, is switched off by default for users in the European Union where stringent privacy rules are in place. It is switched on by default for all other users globally, the spokesman said.

Twitter said in its statement that it has changed the feature so it no longer reveals specific account names in response to requests.

It has also suspended any accounts believed to have been abusing the tool. However, the firm is not sending individual notifications to users whose phone numbers were accessed in the data leak, which information security experts consider a best practice.

REUTERS

Join ST's Telegram channel and get the latest breaking news delivered to you.

A version of this article appeared in the print edition of The Straits Times on February 05, 2020, with the headline 'State actors' likely accessed users' phone numbers: Twitter. Subscribe