Twitter responds to the data leak incident of 200 million users: It was not caused by a vulnerability in Twitter's system
ChainCatcher news, the Twitter Privacy Center responded to the incident of "Twitter user data being sold," stating that after a thorough investigation, there is no evidence that the recently sold data was obtained through a vulnerability in the Twitter system. This data may have been collected from publicly available information from different sources.
Twitter stated that in August 2022, it informed users that it had learned of a vulnerability that leaked Twitter user account information through its "bug bounty program" in January 2022, and that this vulnerability has since been fixed. However, Twitter confirmed at the time that malicious actors had exploited the vulnerability before the issue was resolved and promptly notified affected users and relevant authorities.
ChainCatcher reported on January 5 that over 200 million Twitter account data had been posted on a hacker forum and was available for free download. (source link)