Yes, it's safe to assume that public data is being scraped off Twitter constantly, especially with their history of nerfing the APIs they provide. And for most of the accounts affected by this breach the impact seems low.
But from an engineering standpoint, they failed to audit a somewhat obscure, (presumably) low-traffic endpoint that received an extraordinary amount of attention. It's kind of wild they're willing to admit such incompetence.