5,000,000 seconds is about two months. The attackers simply might not have had enough time to check more numbers than that.
(Assumption: They were checking only one number per second, either to avoid detection or because they were rate-limited.)
(Assumption: They were checking only one number per second, either to avoid detection or because they were rate-limited.)
[1] https://www.bleepingcomputer.com/news/security/twitter-revea...