• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
TechEngage

TechEngage®

Hands-on reviews, research-backed buying guides and technology news.

  • News
    • Internet & Social
    • Gadgets
    • Car Tech
    • Business
    • Science & Health
  • Reviews
  • Buying Guides
  • How-to
  • AI
  • Computing
    • Apps
    • Security
    • Gaming
  • More
    • Tools
    • Puzzles
    • Mobile
  • Launchpad
  • Sign in
TechEngage » Security & Privacy

Twitter security flaw enables hackers access to UK accounts

News

Avatar for Fazeel Ashraf Fazeel Ashraf Follow Fazeel Ashraf on X Published: Dec 30, 2018 · 1:53 PM ET Updated: Jan 1, 2019 · 10:36 PM ET

twitter logo illustration
Twitter to say goodbye to SMS based 2FA for non-Blue users, Image designed by abdugeek / TechEngage
FacebookTweetPinLinkedInPrint
Twitter has a massive security flaw that enabled vigilante hackers to access accounts based in the UK. Hackers from Insinia, a British security firm, exposed the flaw by gaining access to some verified celebrity accounts and posting messages. Insinia was able to pose as celebrities and journalists, without having any knowledge about their passwords. They did this by “spoofing” the cell phone numbers of the users and posting the tweets via text. Most users do not know about this feature. Twitter allows users who have a smartphone and a data plan to tweet via SMS. Users have to link their mobile phone number to their Twitter account and send the tweet as a text to a specific number. Insinia confirmed that it sent the tweets and said they did it to expose the vulnerability. It is unclear how the hackers managed to tweet via the mobile numbers exactly. Twitter uses both shortcodes and long codes to send tweets via SMS. Shortcodes are just three to five digits, whereas long codes look like proper phone numbers. Long codes and shortcodes can vary from country to country, and sometimes different carriers can have different shortcodes as well. As an example, USA uses a shortcode (40404), whereas the UK uses both shortcodes and a long code (+447624800379). A spokesperson for Twitter claimed that the issue had been resolved. Insinia said that it had still managed to send out fake tweets, despite Twitter’s reassurances. The hackers were not able to access users’ Direct Messages or personal details, but they should not have been able to get access in the first place. Insinia’s chief Mike Godfrey said as much. Godfrey claimed his company carried out the testing to prove how text messaging can be exploited to verify people’s identities. Godfrey added:
“We should not be using 50-year old technology. It is massively flawed by design. Even someone completely unskilled could carry [out] this attack within half an hour. This took us 10 minutes.”
The Insinia’s chief believes the security loophole might have been in existence for a few years at least. He also claimed that his company’s testing might have encouraged Twitter to take better countermeasures. Gizmodo claimed that Twitter has admitted the SMS vulnerability existed since 2012. So essentially, Twitter had six years to clean up their mess, which they failed to do. It seems the bug is the same one or quite similar to the one that existed in 2012. It seems only UK residents have been affected, at least for now. US citizens seem to be safe at the moment. A Twitter spokesperson said Twitter doesn’t “believe there is any significant risk to US-based account holders.” Twitter has been under scrutiny for some time now. The social media network has suffered from numerous Bitcoin scams, and the company was called out for its role in the Russian hacks of the 2016 US presidential election. It will be interesting to see how the company bounces back from these scandals.

Related reading

  • North Korean hackers hacked personal data of 997 defectors
  • Google Shuts down Google+ due to massive data breach
Something incorrect? Report an error in this article. Include a source if you have one; your name and email are optional.

Filed Under: Security & Privacy, Tech News & Analysis Tagged With: Cybersecurity, Data breach, News, Privacy, Security, Security Breach, Twitter, User Data, User privacy

Related Stories

  • Googlebook Shows How Android 17 And Gemini Intelligence Could Reshape Google’S Ecosystem

    Googlebook Shows How Android 17 and Gemini Intelligence Could Reshape Google’s Ecosystem

    AIMay 16, 2026

  • Openai Pauses Advanced-Model Research After Agent Bypasses Network Restrictions

    OpenAI pauses advanced-model research after agent bypasses network restrictions

    Tech News & AnalysisSep 27, 2026

  • Akamai’s $11.6 Billion Anthropic Cloud Deal: Costs, Timeline And Cpu Strategy

    Akamai’s $11.6 billion Anthropic cloud deal: costs, timeline and CPU strategy

    Tech News & AnalysisSep 27, 2026

Stay on top of technology

Get TechEngage reviews, buying guides and news in your feed.

Follow on Google News
FacebookTweetPinLinkedInPrint
Avatar for Fazeel Ashraf

Fazeel Ashraf

Tech & Gaming Editor

Fazeel Ashraf is the Tech and Gaming Editor at TechEngage, covering global tech news, social media, gaming releases, and cybersecurity. An IT graduate of the National University of Sciences and Technology, he has written more than 230 articles across the site's news and features coverage.

Joined TechEngage September 2018First article on TechEngage September 2018

Reader Interactions

Share Your Thoughts Cancel reply

Please read our comment policy before submitting your comment. Your email address will not be used or published anywhere. You will only receive comment notifications if you opt to subscribe below.

Primary Sidebar

Google News

Get TechEngage in your feed

Reviews, news, and buying guides as they publish.

Follow on Google News

Recent Stories

  • Usb C Power Meters Techengage |
    Computing & HardwareBest USB-C Power Meters for Chargers and CablesSep 28, 2026
  • Akamai Anthropic Cloud Techengage |
    Tech News & AnalysisAkamai’s $11.6 billion Anthropic cloud deal: costs, timeline and CPU strategySep 27, 2026
  • Openai Agent Dns Incident Techengage |
    Tech News & AnalysisOpenAI pauses advanced-model research after agent bypasses network restrictionsSep 27, 2026
  • Ai Markets Feat |
    AIThree CEOs Asked to Slow Down. The President Said No and the Market Fell 3 Percent. Hassan Taher on What Actually Happened.Sep 21, 2026
  • Iphone 18 Pro Availability Sept 18 |
    Tech News & AnalysisiPhone 18 Pro and Pro Max Available Today in 65+ CountriesSep 18, 2026

More in Security & Privacy

  • Openai Agent Dns Incident Techengage |
    OpenAI pauses advanced-model research after agent bypasses network restrictionsSep 27, 2026
  • Photo 2023 05 23 19 03 36 Jpg |
    5 Internet Security Suites to Get For Fortifying Your Internet SecurityMay 24, 2023
  • Google Authenticator Gets Cloud Backup Support Jpg |
    Google Authenticator finally gets most awaited cloud sync featureApr 26, 2023
  • Twitter Security Flaw Enables Hackers Access To Uk Accounts
    Twitter’s SMS 2FA is going away today, switch before it’s too lateMar 20, 2023
More Security & Privacy stories →

Footer

Discover

  • About TechEngage
  • Company News & Updates
  • Our Team
  • Advertise
  • Send us a tip
  • Submit your company to TechEngage Launchpad Hot
  • TechEngage Brand Kit
  • Contact us
  • Tools & Calculators

Legal pages

  • Editorial Standards
  • Reviews Policy
  • Our Ethics
  • Corrections Policy
  • Affiliate Disclosure
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions
  • GDPR Compliance
  • Copyright & DMCA

Must reads

  • Best Mechanical Keyboards Under $100
  • Best USB-C Hubs
  • Best Portable SSDs
  • Best Gaming Graphics Cards (GPUs)
  • Best Long-Range Outdoor WiFi Extenders
  • Best Wireless CarPlay Adapters
  • Best Slack Alternatives
  • Best Long-Range Walkie-Talkies

About TechEngage

TechEngage® is an independent technology publication covering tech news, reviews and buying guides.

Founded
2003
Publisher
TechAbout LLC
ISSN
2690-3776
Google NewsRSS feed

© 2026 TechEngage®. All Rights Reserved. TechEngage® is a project of TechAbout LLC.

TechEngage® is a registered trademark in the United States under Trademark Number 6823709 and in the United Kingdom under Trademark Number UK00003417167. It is also ISSN protected under ISSN 2690-3776 and has OCLC Number 1139335774.

Contact team@techengage.com · WhatsApp +1-307-381-8801

Your analytics choice
Allow Google Analytics to help us understand readership? You can use the site without it and change this choice anytime.

Privacy details