vx-underground is reporting that the recent twitter leak of ~400 million accounts was gathered because attackers were able to scrape data out of the API.
Basically, if you tried to log into twitters api using a phone number, it would tell you what username the number was attached to.
so they just cycled through every possible number, and hoovered up every possible number and what account it was attached to. same with email.