This was reported and fixed in January of 2022.
https://hackerone.com/reports/1439026
The question is who is monitoring the bug reports and fixing them now with most of those people likely gone from Twitter.
Reported on Jan 6, fixed on Jan 13. One week to fix from the time it was reported.
In order to get all the records, someone had to take the time to request 5.4 million valid phone numbers or email addresses. It doesn't take that long with a script but unless they were using valid phone numbers they were making 500 million requests and Twitter didn't notice it.
https://hackerone.com/reports/1439026
The question is who is monitoring the bug reports and fixing them now with most of those people likely gone from Twitter.
Reported on Jan 6, fixed on Jan 13. One week to fix from the time it was reported.
In order to get all the records, someone had to take the time to request 5.4 million valid phone numbers or email addresses. It doesn't take that long with a script but unless they were using valid phone numbers they were making 500 million requests and Twitter didn't notice it.

