/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Sources: Google+ bug gave outsiders potential access to private data from 2015 to mid-2018; no disclosure made amid fear of blowback and no evidence of misuse

Google's top executives stopped using it up to 3 years ago Shira Ovide / Bloomberg : No, Google, We Did Not Consent to This  —  The company knew … Craig Timberg / Washington Post : Google to overhaul privacy rules after discovering exposure of user data Ryan Browne / CNBC : Irish data watchdog to request information from Google about social network security bug Jack Purcher / Patently Apple : Google's Pixel 3 Event will be Held in 10 Cities today and they may actually try to Sell Security as a Major Feature Fortune : IMF Warning, Google Data, Virgin Galactic: CEO Daily for October 9, 2018 Kate O'Flaherty / Forbes : Google+ Breach — What Happened, Who Was Impacted And How To Delete Your Account Mohit Kumar / The Hacker News : From Now On, Only Default Android Apps Can Access Call Log and SMS Data Firstpost : Google opted to keep security breach under wraps, feared regulatory scrutiny: Report John Kennedy / Silicon Republic : Google Plus is being shuttered - why? Luana Pascu / Security Boulevard : Google+ Shuts Down Following Undisclosed Data Breach Chris Mills / BGR : Google is killing Google+ after security flaw exposed user information Tweets: Shira Ovide / @shiraovide : The data privacy scandals at Google and Facebook have a root cause: There is no true informed consent in our digital lives. https://www.bloomberg.com/... pic.twitter.com/ZQ7xgquitr Deepa Seetharaman / @dseetharaman : It's not the crime. It's the cover up. https://www.wsj.com/... pic.twitter.com/7FhYYDj8mR Doug MacMillan / @dmac1 : Did Google have any obligations to disclose this incident to the public? Companies may be liable to notify users of a data breach if they know certain types of data was accessed. Because Google didn't know what data was accessed, it's unclear what laws may apply. @reutersbiz : MORE: Google says it discovered and immediately patched the bug in March 2018 $GOOGL pic.twitter.com/FcUZSyomLb @reutersbiz : MORE: Google says it cannot confirm which users were impacted by the bug $GOOGL pic.twitter.com/GUoaItbxoP Ryan Mac / @rmac18 : The story here isn't really the potential data breach (which may affected hundreds of thousands) or that Google is shutting down Google+. It's that Google's execs knowingly avoided disclosing an issue because they knew it'd invite gov scrutiny & bad PR. http://www.wsj.com/... Scott Austin / @scottmaustin : Cover-up by Google: Revealing the data leak would likely result “in us coming into the spotlight alongside or even instead of Facebook despite having stayed under the radar throughout the Cambridge Analytica scandal,” Google memo says https://www.wsj.com/... $GOOGL Rat King / @mikeisaac : dark comedy: google plus PR spent five years trying to dissuade writing about the network's absymal usage numbersnow that it leaked everyone's data, google can't get enough of telling people how no one used it http://twitter.com/... Arvind Narayanan / @random_walker : Important counterpoint by @tqbf to the “Google opted not to disclose breach” story. This vulnerability was fixed before it was exploited. That happens thousands of times every year. Requiring disclosure of all of these would be totally counterproductive. https://news.ycombinator.com/ ... pic.twitter.com/CFaWTBS7kM Steve Kovach / @stevekovach : “Sundar Pichai was briefed on the plan not to notify users after an internal committee had reached that decision...” https://www.wsj.com/... Ken Yeung / @thekenyeung : So Google exposed consumer data, but opted NOT to inform user(s) because it could draw regulatory scrutiny and “cause reputational damage”?Steps Google will take now include basically “permanently shutting down all consumer functionalty of Google+”. http://www.wsj.com/... Rob Price / @robaeprice : interesting euphemism for a security lapse that compromised hundreds of thousands of users' data that Google initially opted not to disclose https://www.blog.google/... pic.twitter.com/JJV8jWGG58 @kawaiiguyla : Google+ is shutting down. (Can't say many of us didn't see this coming for years...) I am more curious as to how this impacts @YouTube - it had required creators to link their accounts to G+ for brand accounts & enable manager access. I'm guessing a fix is in the works? http://twitter.com/... Melissa / @0xabad1dea : There's the PR hit from disclosing a possible breach. Then there's the PR hit from it coming out you decided not to disclose a possible breach affecting half a million users because it might attract regulatory attention http://twitter.com/... Ryan Satterfield / @i_am_ryan_s : This WSJ article on the Google+ bug is factually incorrect in many ways. 1. You do not have to disclose a flaw that no one used! 2. No one used it, no one found it, so why is this an article? 3. Stop fear-mongering! https://www.wsj.com/... Christopher Mims / @mims : Google: we have plausible deniability, so we didn't notify you that your data was at risk... http://twitter.com/... Matt Stoller / @matthewstoller : Same dynamic as Facebook. There's a 2011 FTC consent decree with Google, so this is recidivism. Every violation is a possible $40k fine. http://twitter.com/... Ryan Gallagher / @rj_gallagher : CEO @SundarPichai “was briefed on the plan not to notify users after an internal committee had reached that decision”; the episode “shows the company's concerted efforts to avoid public scrutiny of how it handles user information.” https://www.wsj.com/... Brian McCullough / @brianmcc : Has anyone made this point yet? Pichai refused to testify to congress because he couldn't. He would have either had to perjure himself or reveal this bug in real time before the committee. http://www.techmeme.com/... Alexia Bonatsos / @alexia : But also a “lack of use” http://www.techmeme.com/... http://twitter.com/... Josh Constine / @joshconstine : “90% of Google+ sessions were under 5 seconds” or how your ghost town became a liability. Is this karma for copying Facebook & being holier-than-thou on privacy? http://techcrunch.com/... Chris Davies / @c_davies : You can probably file Google+'s demise under “a huge privacy bug exposed half a million people's data but nobody cared enough about our social network to exploit that” https://www.slashgear.com/... Chris Davies / @c_davies : Google's thinking here - to do an internal assessment, decide a breach potentially affecting 500k ppl's data didn't meet disclosure levels, and so sit on it - seems seriously faulty. If it's a non-issue that should be down to users to decide. Chris Davies / @c_davies : According to the WSJ the security loophole was exposed between 2015 and March 2018. Google kept API logs for two weeks. Were you affected? Google says pic.twitter.com/si4aXw3JLY

Wall Street Journal

Context & Ripple Effects

The disclosure lands in the wreckage of a product Google had already abandoned emotionally: reporting has shown the company was so fixated on beating Facebook that it neglected Google+, and its own top executives stopped using the network up to three years before the bug surfaced. The exposure itself ran through an API permission boundary — outsiders could potentially reach private profile data from 2015 until the fix in mid-2018.

The political backdrop is the post-Cambridge Analytica climate, where Facebook's data practices drew congressional and FTC heat and where apps were caught piping sensitive user data to Facebook through its analytics SDK (heart rates, pregnancy intent, home listings). Google's decision to sit on the bug rather than disclose it is the sharpest possible contrast with that environment.

First-order effects

  • Google kills consumer Google+ outright and commits to overhauling its privacy rules, while the Irish data watchdog formally demands information about the bug and how the company handled user data.
  • Developers building on Google's social APIs face immediate access revocation, since the leak path ran through exactly those third-party endpoints.

Second-order effects

  • Regulators beyond Ireland — Congress and the FTC among them, given the Cambridge Analytica precedent — gain a fresh case study of a major platform choosing silence over disclosure, pressuring all US platforms toward mandatory breach-notification standards.
  • Rivals' developer programs come under the same lens: if Google's own APIs leaked private fields for three years unnoticed, Facebook's SDK ecosystem and similar data-sharing pipes face renewed audit pressure.

Third-order effects

  • The episode hardens a structural norm question: platforms disclosing security failures only when forced, a pattern Google repeated later when it disclosed shutting down a hacking group without revealing it was an allied counter-terrorism operation (the undisclosed CT operation) — pointing toward regulation replacing voluntary transparency.
  • Notably, Google absorbs less user outrage than Facebook did because its services are seen as genuinely useful (the asymmetry in breach backlash), which may embolden large platforms to gamble on quiet fixes — making external oversight, not reputation, the real enforcement mechanism.

The trend: Platform data governance is shifting from voluntary, self-timed disclosure by big tech toward regulator-driven accountability, with each undisclosed exposure narrowing the industry's room to police itself.