Skip to main content
  1. Home
  2. Social Media
  3. Computing
  4. News

Twitter squashes security bug leaking direct messages since 2017

Add as a preferred source on Google
Direct Messages on Twitter
Image used with permission by copyright holder

When you send a direct message on Twitter, you expect the information to be kept private between you and the intended recipient; unfortunately, Twitter revealed today that due to a software bug, some direct messages might have ended up in the wrong hands. The error may have affected communications between some of Twitter’s user base and business accounts on the platform as far back as May 2017.

According to Twitter, the company recently discovered a bug within its Account Activity API — a programming interface that allows business developers to source information regarding other accounts in real-time. The API feature is regarded as a source of premium information access that allows businesses to connect with customers and monitor social streams.

Recommended Videos

If you direct messaged a business account between May 2017 and September 10, 2018, it is possible that your information was unintentionally routed to a registered developer. Instead of your private information being shared only with the intended recipient, the developer of the platform used by the business may have also received its contents. Businesses that users may have interacted with include accounts for customer support, airlines, banks, and more.

The team at Twitter stresses that the data breach was fixed within hours of being discovered, but that still means that the bug ran for sixteen months without being detected. The company has also noted that the software glitch affected less than 1 percent of people on Twitter, but with Twitter having sixty-eight million active users as of early 2018, that could mean that up to approximately 680,000 people were affected.

Twitter has begun reaching out via in-app communication and website notices to any users who may have been compromised by the incident. The company’s policies require developer partners to dispose of any information that they may have unintentionally received. As expected, Twitter is hoping that developers will do the right thing and delete any intercepted messages.

Most businesses typically do not ask consumers to send sensitive information via direct messages, but if you have submitted any information to a business account via direct messages that you deem sensitive, it is vital to keep an eye out for any fraudulent activity that may result from the incident.

Michael Archambault
Former Digital Trends Contributor
Michael Archambault is a technology writer and digital marketer located in Long Island, New York. For the past decade…
X’s creator payouts are changing, and original content is the new currency
The platform is replacing Revenue Sharing with a program designed to reward creators who actually make something.
X Twitter on iPhone

X is changing the rules for creators yet again. This time, the platform wants to put less emphasis on simply generating engagement and more on actually making something original. X is replacing its controversial Creator Revenue Sharing program with a new initiative called Original Content Rewards, which will officially launch on September 8, 2026. The existing Revenue Sharing program will continue paying participating creators through September 7, after which the new system takes over.

X wants to reward creators, not engagement farmers

Read more
Snapchat’s Spotlight algorithm now favors human-made videos over AI-generated ones
Snapchat is taking a firm stance against AI slop.
Snapchat-App-Store-open-on-iPhone

If you've been uploading fully AI-generated videos on Snapchat in hopes of earning rewards, it might be time to rethink your strategy. Snapchat has announced changes to Spotlight that prioritize authentic, original creativity over content created entirely by artificial intelligence. The company says its recommendation system will now favor videos made by real creators, while fully AI-generated submissions will no longer qualify for monetization.

So what's changing on Spotlight?

Read more
LinkedIn is crowdsourcing its fight against AI slop
The company is rolling out a new button that lets you flag posts that seem AI generated.
LinkedIn seems like AI slop button

LinkedIn has a serious AI slop problem, and it's now turning to its own users to help fix it. The platform is rolling out a new button that lets users flag posts they suspect were generated by AI. It plans to use that feedback to fine-tune the system that decides how much reach a post gets outside a user's own network, based on how AI-generated it appears.

The announcement comes shortly after an analysis by Pangram found that more than forty percent of long-form LinkedIn posts are fully AI-generated, and it suggests that the reach-trimming measures the company rolled out earlier this year haven't been enough on their own.

Read more