According to several reports, and twitter's own report, as many as 5 million accounts may have been vulnerable to actions of a bad actor whilst a log-in action exposed some aspects of a users account, such as phone numbers.
We want to let you know about a vulnerability that allowed someone to enter a phone number or email address into the log-in flow in the attempt to learn if that information was tied to an existing Twitter account, and if so, which specific account.
Twitter recommends users use 2FA
[
privacy.twitter.com...]