Twitter Says Users' Phone Numbers Provided for Security 'Inadvertently' Used for Ad Purposes

The incident marks the latest security mishap for Twitter, but one that could carry with it some legal headaches

Advertisement
By Tony Romm, The Washington Post | Updated: 9 October 2019 10:06 IST
Highlights
  • May have mishandled users' email addresses, phone numbers: Twitter
  • We cannot say exactly how many people were impacted by this, says Twitter
  • "No personal data was ever shared externally"

Twitter said Tuesday that it may have mishandled an unspecified number of users' email addresses and phone numbers, allowing that data to be used "inadvertently" for advertising purposes.

The incident marks the latest security mishap for the social-networking company, but one that could carry with it some legal headaches. Federal regulators penalised Facebook earlier this year for a similar situation.

Advertisement

In a blog post, Twitter explained that users share email addresses and phone numbers with the company for safety and login verification purposes, such as two-factor authentication, which allows people to receive a one-time code that they input along with their password in order to access their account.

The trouble, however, stems from the fact that advertisers can upload their own contact lists to match their customers with Twitter's users. In doing so, Twitter said it "may have matched people on Twitter" to a marketer's list "based on the email or phone number the Twitter account holder provided for safety and security purposes."

Advertisement

"We cannot say with certainty how many people were impacted by this, but in an effort to be transparent, we wanted to make everyone aware," Twitter said. "No personal data was ever shared externally with our partners or any other third parties."

The incident could invite trouble for Twitter in Washington, where regulators who investigated and penalised Facebook for a series of privacy scandals took issue with its handling of phone numbers. In that case, the Federal Trade Commission alleged Facebook deceived users because it "did not disclose, or did not adequately disclose" that phone numbers provided through its security tool for the purpose of two-factor authentication "also would be used by Facebook to target advertisements to those users."

Advertisement

Adding to Twitter's potential troubles, the company finalised an agreement with the FTC in 2011 that alleged the company failed to protect users from security threats. The resulting settlement requires the company to maintain a comprehensive data security policy and refrain from misrepresenting the way it handles and protects users' data, violations of which could carry fines.

"Given that Facebook got dinged for this exact practice, I think it likely meets the threshold of material omission or even deception under Section 5 on its own. That's further compounded by the fact that Twitter is also under order already by the FTC, " said Ashkan Soltani, a former chief technologist at the FTC, citing the portion of law that prohibits unfair or deceptive acts and practices.

Advertisement

Twitter has revealed a number of additional data-security incidents this year. It told users that it may have "inadvertently" collected and shared some location data with an unnamed third-party partner. It also informed users of Twitter's Android smartphone app that a system issue turned off a setting that made their tweets private. Twitter did not disclose the number of users affected in either instance.

Perhaps the most significant security mishap came in August, however, when Twitter CEO Jack Dorsey had his personal account hacked. The move prompted Twitter to disable a feature that allowed users to tweet by text.

© The Washington Post 2019

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Twitter
Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases of the Week (Mar 30th - Apr 5th): From Aamir Khan's Sitaare Zameen Par
  2. Anthropic's Source Code Leak Reveals Critical Details About Claude Code
  3. Redmi Note 15 SE 5G Debuts in India With a Vegan Leather Finish: See Price
  1. Apple's iPhone 18 Pro Models May Not Arrive in Classic Black Finish Just Like iPhone 17 Pro, Tipster Claims
  2. Oppo F33, Oppo F31 Pro Launch Timeline, Price Range Revealed in New Leak
  3. Capcom Adds Original Versions of Resident Evil 1, 2 and Resident Evil 3 Nemesis to Steam
  4. Google's Next Fitbit Wearable Could Launch Without a Display; Said to Require Paid Subscription
  5. CFTC-FTX Settlement: Former FTX Executive Nishad Singh to Pay $3.7 Million, Faces Trading Ban
  6. Slack Upgrades Slackbot With New AI Features to Turn It Into an Enterprise Agent
  7. Australia Mandates Financial Services Licences for Crypto Exchanges Under New Bill
  8. DoT Reportedly Extends SIM Binding Mandate Till the End of 2026
  9. Government Migrates 16.68 Lakh Official Email Accounts to Zoho Cloud, Spends Rs. 180 Crore
  10. Infinix Note 60 Pro India Launch Date Revealed; Company Teases Active Matrix Feature on Rear Panel
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.