How tech CEOs' Twitter accounts got hacked through pre-approved 3rd-party app access
It happened to Mark Zuckerberg. It happened to Sundar Pichai. It happened to Travis Kalanick. And it could happen to you, too. — Want to know how secure your Twitter account is? Here's an easy way to find out.
Context & Ripple Effects
In mid-2016, the hacking group behind the breaches hit Mark Zuckerberg, Sundar Pichai, and Travis Kalanick not by cracking passwords but by posting through third-party apps those CEOs had long ago authorized on their Twitter accounts — a side door most users forget exists. BuzzFeed's follow-up turns the incident into a user audit: check which apps still hold pre-approved access to your account.
The episode reads differently after the corpus that follows it: Facebook later admitted hackers could reach Instagram and Oculus accounts via Facebook Login, Twitter warned developers its bug may have leaked app keys stored in browser caches, and Bloomberg sources detailed years of uncontrolled employee access inside Twitter itself. Delegated access keeps resurfacing as the weak link.
First-order effects
- Zuckerberg, Pichai, and Kalanick each had tweets posted from their accounts without any password compromise, forcing immediate revocation of connected-app permissions and public embarrassment for three of tech's most visible executives.
- Everyday Twitter users are the immediate audience: the story's practical payload is a self-audit of authorized applications, since the same pre-approved access exists on ordinary accounts.
Second-order effects
- Platforms carrying federated identity face the knock-on cost — once a central login like Facebook Connect is breached, the blast radius extends to every downstream service, as Facebook's own admission about Instagram and Oculus showed two years later.
- Twitter's developer ecosystem inherits the risk surface: the 2020 warning that app keys and account tokens may have sat in browser caches shows the same token-based access model failing at the developer tier, not just the user tier.
Third-order effects
- If the pattern holds, security posture shifts from protecting passwords to governing issued credentials — tokens, app grants, and internal employee access — with regulators and enterprises treating every standing authorization as a liability to be expired by default.
- The recurring failures across Twitter's user-facing apps, developer keys, and staff tooling point toward structural pressure on platforms to centralize and audit all forms of delegated access rather than leaving grant management to individual users.
The trend: Account security is migrating from password strength to the governance of delegated access — OAuth grants, login federations, and API keys — where a single compromised credential now spans multiple services.