/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Twitter says it fixed a bug that sent some users' direct messages from their interactions with business accounts to third-party developers, since May 2017

but probably not Ginny Marvin / Marketing Land : Twitter: A bug may have sent some direct messages to business account developers Timi Cantisano / Neowin : For over a year, a Twitter bug has been exposing data to unauthorized parties Dell Cameron / Gizmodo : Twitter Bug That ‘May Have’ Exposed Direct Messages Probably Didn't Expose Anything Shaun Nichols / The Register : Twitter: Don't panic, but we may have leaked your DMs to rando devs Associated Press : Twitter finds software privacy bug affecting direct messages Tim Bradshaw / Financial Times : Twitter bug may have sent users' private messages to external developers Cohen Coberly / TechSpot : Twitter discloses an API bug that redirected users' private messages to third-party developers Alexander Maxham / AndroidHeadlines.com : Twitter Bug Sent Private Direct Messages To Developers For Over A Year Chris Davies / SlashGear : Twitter bug shared Direct Messages for more than a year Margi Murphy / Telegraph : Twitter warns users of year-long glitch that may have shared private messages Tweets: Karissa Bell / @karissabe : Sorry, what ?! My DMs may have been sent to developers for a more than a year?? pic.twitter.com/0ry6pyZIdI @twittersupport : For those who received notifications today, this only involves potential interactions or Direct Messages you have have had with companies using Twitter for things like customer service. Your other DMs are not involved at all. Steve Ragan / @steved3 : This fact seems to be ignored in a number of discussions about the Twitter DM bug. Like I said earlier, the issue is bad, but not catastrophic. Real problem for me is the length of time the bug existed. Why so long? http://twitter.com/... @twittercomms : There's no evidence to suggest that any data was improperly misused or exploited. The bug could only occur if a series of complex criteria were met. There's very little possibility that this happened, but we still want to be thorough. http://www.cnbc.com/... Andrew Teacher / @andrewjteacher : 1/4 Some thoughts on Twitter's DM breach flagged by @MartinSFP would be: 1. Twitter have been far too vague & the post they've issued is packed with jargon and vague phrases, many of which mean nothing to the man on the street. Post is here: http://help.twitter.com/... Matthew Panzarino / @panzer : Twitter is very bad at communicating in crisis mode. This has come up over and over in various breach situations. It seems like this is a suuuuuuper minor thing that is being communicated as a major breach. Martin Bryant / @martinsfp : So Twitter says it's a very specific type of DMs. The wording they used in alerting users should have been a lot clearer. http://twitter.com/... Andrew Teacher / @andrewjteacher : 4/4 To preserve its reputation here and avoid this spiraling Twitter should front this up, speak in clearer, plainer English and be more transparent over how many people were affected and what the volume of leaked material was. Martin Bryant / @martinsfp : Good points here. My DMs in early September included a journalist reporting out a story. It was nothing salacious in that case, but those kinds interactions happen constantly across the userbase. http://twitter.com/...

TechCrunch Zack Whittaker

Context & Ripple Effects

Twitter's disclosure that a bug running since May 2017 may have routed direct messages from user interactions with business accounts to third-party developers fits a pattern the company kept repeating: months later it admitted the "Protect your Tweets" setting had been silently disabled on Android for years, then disclosed ad-targeting bugs that shared user data with ad partners without consent.

The company's habit of downplaying flaws was already under strain before this — researchers had just shown that [[a:937032|a bug Twitter minimized in 2012 could still be used to hijack celebrity accounts via a phone number]]. Each new multi-year disclosure lands on that accumulated credibility deficit, and the fact that this one involves the developer API rather than just settings makes it harder to frame as a contained glitch.

First-order effects

  • Users who exchanged direct messages with business accounts between May 2017 and the fix are the exposed population, and any third-party developer whose apps touched those business-account flows may have received message content without authorization.
  • Twitter's own statement that there is no evidence of misuse becomes the load-bearing claim — it shifts the burden of reassurance onto a company that cannot audit what every recipient developer did with the data.

Second-order effects

  • Businesses using Twitter DMs for customer service face a trust problem with their own customers, since the channel they chose leaked conversations to unknown developers — giving them reason to steer support toward channels they control end-to-end.
  • Every subsequent disclosure in the series, including the 2020 warning that developer app keys and account tokens were stored in browser caches, compounds scrutiny of Twitter's developer platform specifically, raising the cost of the API access model the company relies on for its ecosystem.

Third-order effects

  • A string of self-disclosed, multi-year bugs points toward external verification replacing platform assurances as the basis of trust — regulators and enterprise customers increasingly treating 'we found no evidence of misuse' as insufficient, which pressures all major platforms to shorten detection windows and tighten third-party data access by design.

The trend: Platform privacy is moving from periodic self-disclosure of long-lived bugs toward externally enforced data-governance obligations, as each multi-year leak erodes the credibility of companies auditing themselves.