The bug was brought to light through a bug bounty program in December 2021 and was patched by Twitter—but not before hackers accessed users’ private phone numbers and email addresses, which they started selling in July.
While Twitter said that it “deeply regretted” the breach, security experts cautioned that the breadth of what hacks will do with the data remains to be seen.