Google Apps bug has leaked private whois data for 280K domains since mid-2013
and didn't notice for 2 years Sead Fadilpaši / ITProPortal : Google Apps leaks raft of hidden WHOIS data Tweets: Sbi / @tweetsbi : “a reminder why people do well to provide false information when registering for anything online.” http://arstechnica.com/... by @dangoodin001 Izzy Galvez / @iglvzx : The Google/eNom domain management system has always been flaky. This is such bad news: http://arstechnica.com/...
Context & Ripple Effects
In March 2015, Ars Technica reported that a bug in Google Apps' domain management — run through registrar eNom — had been publishing hidden WHOIS fields (names, phone numbers, and other contact details) for 280,000 domains since mid-2013, unnoticed for roughly two years. The story landed amid an already rough stretch for Google on data handling: weeks earlier, security researchers had published App Engine exploits after three weeks of silence from Google, and the company's disclosure instincts were becoming a story of their own.
What makes this incident more than a one-off is how it foreshadowed the pattern later documented in a leaked internal tracker: the database of thousands of privacy and security issues from 2013 to 2018 covers exactly this window, and includes the parallel case of a Google+ flaw kept quiet over fear of blowback. The WHOIS leak was thus an early data point in a decade-long record of long-lived, undisclosed exposures at Google.
First-order effects
- Roughly 280,000 domain owners who paid for private WHOIS registration through Google Apps saw their names, phone numbers, and contact details exposed publicly for up to two years without notification.
- eNom's privacy-protection offering takes a direct credibility hit, since the leak originated inside the Google/eNom management layer rather than at the registry level.
Second-order effects
- Registrants respond by trusting privacy services less: as one observer quoted in the coverage put it, people do well to provide false information when registering domains — degrading the accuracy of WHOIS data for everyone, including legitimate buyers and investigators.
- Competing registrars can market their own privacy handling against Google's, pressuring the whole reseller chain (Google as reseller, eNom as upstream registrar) to prove where private fields actually live and who can see them.
Third-order effects
- Repeated multi-year exposures of this kind strengthen the structural argument for retiring publicly searchable WHOIS altogether in favor of gated, per-request disclosure — the direction domain policy subsequently moved.
- If the pattern documented across the 2013–2018 period holds, disclosure becomes the battleground: regulators and customers increasingly treat how long a platform sits on a known data leak as the real measure of its trustworthiness, not just the leak itself.
The trend: Large platforms' recurring multi-year, quietly-unfixed data exposures are pushing both domain policy and customer expectations toward gated access to registration data and harder scrutiny of corporate self-disclosure.