>Among the 1,900 phone numbers, the attacker explicitly searched for three numbers, and we’ve received a report from one of those three users that their account was re-registered. I wonder if this was a curious attacker trying to see what they could do with their access, or a targeted attack.
The page is also quite vague about how the attacker got these 1900 phone numbers. It seems to imply that they were just the ones around when the attacker got access. But it doesn’t actually state that clearly. Were they 1900 random numbers or were they chosen somehow? The latter is of course far worse. They also apparently have logs of the attacker searching out three specific accounts within these 1900. That seems o…
Any Signal accounts that did not start that process during that time would not be able to be intercepted or accessed since Twilio has no means to begin it. The three specific accounts mentioned would be the cases found that the verification message was accessed through Twilio to register the account on the attacker's device.
So yes, in effect the 1900 were only the ones around when the attacker got access. Whether the specific three were targeted attacks or random messing around isn't clear though.