Skip to main content
  1. Home
  2. Social Media
  3. Computing
  4. News

Twitter squashes security bug leaking direct messages since 2017

Add as a preferred source on Google
Direct Messages on Twitter
Image used with permission by copyright holder

When you send a direct message on Twitter, you expect the information to be kept private between you and the intended recipient; unfortunately, Twitter revealed today that due to a software bug, some direct messages might have ended up in the wrong hands. The error may have affected communications between some of Twitter’s user base and business accounts on the platform as far back as May 2017.

According to Twitter, the company recently discovered a bug within its Account Activity API — a programming interface that allows business developers to source information regarding other accounts in real-time. The API feature is regarded as a source of premium information access that allows businesses to connect with customers and monitor social streams.

Recommended Videos

If you direct messaged a business account between May 2017 and September 10, 2018, it is possible that your information was unintentionally routed to a registered developer. Instead of your private information being shared only with the intended recipient, the developer of the platform used by the business may have also received its contents. Businesses that users may have interacted with include accounts for customer support, airlines, banks, and more.

The team at Twitter stresses that the data breach was fixed within hours of being discovered, but that still means that the bug ran for sixteen months without being detected. The company has also noted that the software glitch affected less than 1 percent of people on Twitter, but with Twitter having sixty-eight million active users as of early 2018, that could mean that up to approximately 680,000 people were affected.

Twitter has begun reaching out via in-app communication and website notices to any users who may have been compromised by the incident. The company’s policies require developer partners to dispose of any information that they may have unintentionally received. As expected, Twitter is hoping that developers will do the right thing and delete any intercepted messages.

Most businesses typically do not ask consumers to send sensitive information via direct messages, but if you have submitted any information to a business account via direct messages that you deem sensitive, it is vital to keep an eye out for any fraudulent activity that may result from the incident.

Michael Archambault
Former Digital Trends Contributor
Michael Archambault is a technology writer and digital marketer located in Long Island, New York. For the past decade…
Instagram is finally giving your old posts a soundtrack do-over
Instagram lets creators refresh old posts without nuking their engagement
Opening settings in Instagram

Instagram is rolling out a Replace Audio feature that lets users change the in-app music attached to feed posts and carousels after they have already been published. The original post stays live throughout the process, preserving its likes, comments, and shares.

Your post keeps all its engagement

Read more
X finally rebuilt its neglected Android app, and it only took a year
X’s Android app was so rough, the company rebuilt the whole thing
X Android app gets a complete overhaul

Android users have spent years receiving the rougher version of X. Now, the company has finally decided that patching the old app was no longer enough. X has released a completely rebuilt Android app following nearly a year of development. Existing users can access it by installing the latest update through the Google Play Store, so there is no separate replacement app to download.

X tore the old foundation out

Read more
New X phishing scam uses fake login alerts to steal your account
Scammers have copied X's own security emails almost pixel for pixel, and people are falling for it.
X app store listing on iPhone

You open your inbox and see an alert claiming someone just logged into your X account from an unfamiliar device. Your first instinct is to click through and lock things down immediately. That instinct is exactly what a new phishing scam is counting on.

As reported by The Guardian, a wave of fake X security emails is currently doing the rounds. They claim a new device has logged into your account and urge you to click a link to reset your password or review app access. 

Read more