/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Inside the FBI's complaint against two ex-Twitter employees who allegedly accessed personal info of thousands of users on behalf of Saudi Arabia for $300K+

Ali Alzabarah was panicked.  His heart raced as he drove home from Twitter's San Francisco headquarters in the early evening on Dec. 2, 2015.

BuzzFeed News Alex Kantrowitz

Context & Ripple Effects

The DOJ charged two ex-Twitter employees with spying for Saudi Arabia in November 2019, arresting one, after investigators found one of them had accessed roughly 6,000 accounts back in 2015 (the charges against the pair). BuzzFeed's piece goes inside the underlying FBI complaint: it names Ali Alzabarah, traces his panicked drive home from Twitter's San Francisco headquarters on Dec. 2, 2015, and puts a dollar figure on the operation — more than $300,000 paid for personal user data on kingdom critics.

That matters because the complaint reframes the case from an HR problem into state espionage run through platform insiders: the alleged target list was Saudi dissidents, and the payment trail runs through intermediaries tied to Riyadh rather than through any external hack.

First-order effects

  • Twitter faces direct scrutiny of its insider-access controls, since the complaint alleges employees used legitimate internal tools to pull personal data on thousands of users — no exploit required.
  • The FBI gains a documented money trail (over $300,000) tying the data access to Saudi Arabia, sharpening the case against both ex-employees and the recruiters who approached them.

Second-order effects

  • Other major platforms are pushed to audit how easily support and engineering staff can query user records, because the same recruitment playbook — targeting nationals of a foreign state employed at US consumer-data companies — transfers directly to their workforces.
  • Twitter's own handling of implicated Saudi figures comes under pressure: the company kept Bader al-Asaker, an MBS aide tied to an employee-recruitment plot, verified with 2.1M followers (its decision on al-Asaker's account).

Third-order effects

  • If the pattern holds, employee vetting and insider-threat monitoring become a counterintelligence requirement for US consumer platforms, with the Abouammo prosecution — conviction in August 2022 (jury verdict) followed by a 3.5-year sentence — establishing that insider espionage carries criminal consequences, not just firings.
  • Reporting that the 2015 internal-data access fed information preceding Saudi dissidents' disappearances (the breach's human cost) points toward regulation treating user-data access logs as a national-security matter, not merely a privacy one.

The trend: US social platforms are becoming targets of state espionage through recruited employees, turning insider data access into a counterintelligence and regulatory problem rather than a routine security incident.

Discussion

  • @kantrowitz Alex Kantrowitz on x
    Two well-liked Twitter employees accessed thousands of users' private information and illegally passed it to the Saudi Royal Family, per the FBI. It is a crazy story. With many twists and turns, including a fake invoice, an escape from SF, and more. https://www.buzzfeednews.com/ …
  • @kantrowitz Alex Kantrowitz on x
    The key for the Saudis, according to the FBI, was enlisting Ali Alzabarah, a site reliability engineer who had vast access to Twitter's infrastructure. Alzabarah fled to Saudi Arabia and is now a high ranking official in Mohammed Bin Salman's Misk Foundation.
  • @zeynep Zeynep Tufekci on x
    This is a very significant story given the oversized role Twitter plays in Saudi Arabia's public sphere (functioning perhaps as *the* public sphere in the kingdom)—and this breach will likely lead to people being jailed or executed. (If it hasn't already. It probably has). https:…
  • @drewharwell Drew Harwell on x
    “The deeper damage was done to those Twitter users in Saudi Arabia, he said. He believes some were arrested and tortured.” https://twitter.com/...
  • @carnage4life Dare Obasanjo on x
    Given the reality how tech works (i.e. someone needs backend database access) and that governments are interested in who's behind various social media accounts, this story shouldn't be surprising and yet it's still mind blowing. 🤯 https://www.buzzfeednews.com/ ...
  • @rayhana Rayhana Sultan on x
    If you wonder why Twitter discontinued its verification request, it's because it hired Muslim Saudi staff to verify users who collected the phone number, email address and passed them to Saudi Crown Prince's butchers. It's a shame that the West suck up to these animals. https://t…
  • @anildash Anil Dash on x
    This story is stunning, and I'm not easily surprised. And it immediately raises the question of what's happening at the social networks run by companies who *willingly* do business with people like MBS. https://twitter.com/...
  • @deaneckles Dean Eckles on x
    Consistent with my long-standing view that all major world governments have moles at all major Internet companies. https://twitter.com/...
  • @glukianoff Greg Lukianoff on x
    My shiny new dystopia is also occasionally a bad spy novel https://twitter.com/...
  • @katienotopoulos Katie Notopoulos on x
    This is absolutely wild - not just that spies infiltrated Twitter jobs and gave user info to MbS - but how Twitter apparently barely notified the dissidents whose privacy was breached https://www.buzzfeednews.com/ ...
  • @kimzetter Kim Zetter on x
    “We hear a lot about tech companies' outside threats — Russian bots! — but those I spoke with said insiders working for foreign governments are far more dangerous. All it takes is one well-placed employee to become a mole, and a country can get identifying data on dissidents” htt…
  • @johnpaczkowski John Paczkowski on x
    “All evil begins with a verification request.” https://www.buzzfeednews.com/ ... via @kantrowitz
  • @clarajeffery Clara Jeffery on x
    However awful and far reaching you think MBS' evil network extends, it's probably greater: https://www.buzzfeednews.com/ ...
  • @scottlucas Scott Lucas on x
    “One day the general counsel came to me and said there was this crazy thing that happened. They're out of the company. You can never talk about it,” a former Twitter executive told @BuzzFeedNews https://www.buzzfeednews.com/ ... via @Kantrowitz
  • @rmac18 @rmac18 on x
    blue checks will be the downfall of mankind https://twitter.com/...
  • @kantrowitz Alex Kantrowitz on x
    We hear a lot about tech companies' outside threats — Russian bots! — but those I spoke with said insiders working for foreign governments are far more dangerous. All it takes is one well-placed employee to become a mole, and a country can get identifying data on dissidents