Twitter said in a security advisory that the security weakness exploited by a threat actor in December 2021 was uncovered and fixed in January as part of the company’s bug bounty program.
The threat actor was reportedly able to input an email address or phone number, see if it was linked to a Twitter account, and then access the associated account ID.