Not saying it's good, but a lot better than it originally sounded. The two domains pointing to the same IP is pretty rare. The place that got the sensitive information is used to dealing with it anyway (ie maybe AirFrance can read personal information that I sent to the post office - they will both hopefully have their own policies on dealing with such information).
With these details I think any personal information I included in DMs is less likely to be used maliciously through this bug than e.g. from someone accessing my twitter account directly or through a malicious actor at the Brand Account I intended to share with.