The email addresses and phone numbers of 10,000 Twitter may have been exposed due to a bug in the website's password recovery feature.
The incident occurred last week and personal information was exposed for 24 hours. The company notified those affected by the bug, while warning that any attempt to exploit it would result in penalties:
“Any user found to have attempted to exploit the flaw to obtain unauthorized access to third-party accounts will be permanently suspended and, where appropriate, the relevant law-enforcement authorities will be notified so that they can conduct a thorough investigation and bring charges”, Twitter said in a blog post.
It is not uncommon for various website functions and features to be breached for the purpose of intercepting user information, such as email addresses and phone numbers. In 2012, Facebook imposed a limit on the number of phone lookups via its mobile site, because a security flaw could allow attackers to perform successive phone number searches and map them to existing users.
As is known, Twitter offers a login verification feature that requires users to provide a one-time code in order to verify their identity. Users receive this code on their mobile phone as a second verification step, after they have first entered their regular password.
Additionally, the social network offers another feature for user security, requiring supplementary information such as the user's email address or phone number, for resetting the account password. This option can be found on the account privacy settings page. If the feature has not been enabled, initiating the password reset process requires only the account username.
Twitter users should also consider using a strong password with more than 10 characters, periodically reviewing the login history on their account, as well as checking the apps tab and revoking access to all apps that are no longer used.

