Sources: Saudis groomed a Twitter employee to spy on accounts of dissidents; he was investigated and fired in Dec. 2015 after Western intelligence warnings
Some years ago an investor I met at a TechCrunch … Jordyn Holman / Bloomberg : McKinsey Is ‘Horrified’ That Saudi Arabia Report May Have Been Misused CNET : Twitter employee may have spied on users for Saudis, says report Tweets: McKinsey & Company / @mckinsey : Statement in response to today's New York Times article https://nyti.ms/2yPncs7 pic.twitter.com/rJtMzDOclG Avi Asher-Schapiro / @aaschapiro : The New York Times has obtained documents showing the consultancy firm McKinsey helping Saudi Arabia identify influential Saudis who opposed the government's line on Twitter—individuals who were later imprisoned & targeted with sophisticated spyware https://www.nytimes.com/... pic.twitter.com/hlwkYZaOa1 Anand Giridharadas / @anandwrites : Blood-curdling. @mckinsey reportedly provided the Saudis with a nine-page report identifying the three dissidents fueling Twitter criticism of the kingdom. Saudi arrested one, jailed two brothers of another, and shut down the third, anonymous account. https://nyti.ms/... pic.twitter.com/eJM1Q2ggr7 Vanessa Parra / @parrav : Anyone with a modicum of knowledge about Saudi Arabia's history and positioning would have read between the lines. Any logical, reasoned individual would have seen this. Perhaps you did not want to see. Perhaps that is the problem. http://twitter.com/... Andy Slavitt / @aslavitt : I've been waiting on a statement from McKinsey for their work identifying Saudi critics, some of whom have been imprisoned from that work. The one that finally came both confirms the facts and denies accountability. http://twitter.com/... Runa Sandvik / @runasand : “Twitter executives first became aware of a possible plot to infiltrate accounts at the end of 2015, when Western intel officials told them that the Saudis were grooming an employee to spy on the accounts of dissidents and others.” https://www.nytimes.com/... https://twitter.com/... Holly Fιυeroα O'Reιlly / @aynrandpaulryan : The Saudis groomed a Twitter employee who acted as a mole to spy on twitter user accounts. He was fired under suspicion, left town with nearly none of his belongings, moved to Saudi Arabia, and now works with the Saudi government. https://nyti.ms/2R60weV pic.twitter.com/bnCwdKPIND Luke Baker / @bakerluke : Sounds like they're saying they scoured Twitter, drew up a list of influential Saudi critics, gave the list to a non-government body and are shocked, shocked, that it was used in some other capacity http://twitter.com/... Oliver Darcy / @oliverdarcy : Wow, @nytimes reports that the Saudis groomed a Twitter employee with access to users' personal info and activity to spy on dissidents https://www.nytimes.com/... pic.twitter.com/NLoBiSDMuy Jay Rosen / @jayrosen_nyu : The Times said a @McKinsey report on social media usage “was issued” and then bad things happened to critics of Saudi Arabia who were prominent on social. McKinsey in its response is saying there was no issuing of a report because it was for internal use. pic.twitter.com/rto4lsbl5e https://twitter.com/... Andrew Prokop / @awprokop : .@McKinsey helped the Saudi government identify some of their most vocal Twitter critics. What happened next will not surprise you. http://www.nytimes.com/... http://twitter.com/... Mike Masnick / @mmasnick : And this tweet has even more retweets, and also ignores that the article says it was prepared for internal use, not for the Saudis, and was not given to the government. If that turns out to be wrong, it's a big deal, but reporters shouldn't misrepresent. http://twitter.com/... Glenn Kessler / @glennkesslerwp : So the Saudi government tried to put a spy in the top ranks of Twitter? Jeez. Lots of eye-opening material in this @nytimes story https://www.nytimes.com/... pic.twitter.com/koYwwoGmYO Robby Starbuck / @robbystarbuck : This is a really bad story for Twitter and will strengthen the case for regulating social media giants. Given the private communication that happens on Twitter, Facebook & Instagram there should be extreme safeguards + supervision for any employee to access accounts. http://twitter.com/... @pinboard : The biggest insider threat to Twitter sits in the CEO's office http://twitter.com/... Melissa / @0xabad1dea : I really don't think any major social media company fully appreciated or prepared for this class of risk and it's a little late now http://twitter.com/... Tom Gara / @tomgara : I'm trying to imagine “find our enemies, bring us a list of names” turned into McKinsey speak. Perform stakeholder analysis to identify key negative human information vectors for engagement through corrective isolation Akin Unver / @akinunver : States' infiltration of big tech companies has probably been going on for a long time; this could be just one of many cases we don't know about. http://twitter.com/... Nicholas Grossman / @ngrossman81 : Infiltrating social media companies is a logical move for intelligence agencies: -Gain administrator access for surveillance -Understand inner-workings, so they can figure out how to manipulate the platforms -Ideally, place someone who can influence platforms from the inside 1/2 http://twitter.com/... @onekade : This is why it's important to restrict access to information internally. Jaw dropping security problem requiring an immediate fix. All tech companies must take notice. http://twitter.com/... @mollyjongfast : Twitter employees spying on dissidents for the Saudi government is not where I thought this was going but WHAT????!?!???!?!?!?!?? http://twitter.com/... Dana Shell Smith / @ambdana : Glad this is getting attention. It isn't a surprise to me, I watched the Saudi trolls (and their partners) do it to Qatar. http://twitter.com/... Rat King / @mikeisaac : twitter was approached by western intelligence officials in December of 2015. It appeared KSA was grooming an employee to spy on accounts of dissidents. the employee was investigated and terminated. user accounts he had accessed were sent notices.http://twitter.com/...
Context & Ripple Effects
The New York Times report lands mid-arc: it reveals that Twitter caught and fired an employee in December 2015 after Western intelligence warned the company he had been groomed by Saudi Arabia to surveil dissident accounts — an internal breach that stayed quiet for three years. The same reporting surfaces McKinsey's alleged role, with documents showing the consultancy helped identify influential Saudis who opposed the government's line on Twitter, though McKinsey denies issuing the report to Riyadh or responsibility for any misuse.
What makes this more than a personnel story is what follows from it: the DOJ later charged two ex-Twitter employees with spying for the kingdom, one allegedly accessing 6,000 accounts in 2015 (DOJ charges against two ex-Twitter employees), Bloomberg reported that data pulled in that breach fed the disappearance of Saudi dissidents (data from the 2015 breach linked to dissidents' disappearances), and a Canadian activist sued NSO Group over spyware used against Khashoggi contacts (NSO Group lawsuit over WhatsApp spying tied to Khashoggi) — together sketching a full pipeline from platform insiders to physical targeting.
First-order effects
- Twitter faces immediate questions about why its December 2015 investigation and firing were never disclosed publicly, and whether its insider-access controls could detect state-directed grooming rather than ordinary misuse.
- McKinsey is forced into public damage control — its statement denying delivery of the report to the Saudi government — because the allegation ties its client work to the identification of individuals later targeted.
Second-order effects
- Western intelligence services now treat consumer-platform employees as a counterintelligence surface, raising the bar for background screening and access auditing at companies whose user data doubles as a dissident map.
- Riyadh's reputation risk spreads to its Western vendors and partners: consultancies, platforms, and investors tied to Saudi programs face scrutiny over whether their deliverables enable repression, pressuring due-diligence practices across the board.
Third-order effects
- If the pattern holds — insider recruitment plus consultancy-produced target lists plus commercial spyware — diaspora dissent moves from a free-speech question to a national-security one, pushing regulators toward mandatory disclosure of state-directed breaches and tighter rules on who inside platforms can touch account-level data.
- Platforms' trust-and-safety apparatus gets redefined around hostile-state insiders, making employee access logs and anomaly detection a compliance expectation rather than a security nicety.
The trend: Authoritarian states are assembling multi-channel surveillance pipelines against diaspora critics — recruiting platform insiders, commissioning target lists from Western consultants, and deploying commercial spyware — forcing US platforms and their vendors into a counterintelligence role they never designed for.