Researcher: major sites like Wish and Mailchimp were leaking email addresses to ads and analytics companies including Facebook and Twitter via URL query strings
Breaches have been found on websites including Wish.com, JetBlue.com, Quibi.com, WashingtonPost.com, NGPVan.com and numerous other organizations...
Zach Edwards
Context & Ripple Effects
Zach Edwards' finding shifts the email-exposure story from breaches to plumbing: Wish, Mailchimp, JetBlue, Quibi, the Washington Post and NGPVan were passing user email addresses to Facebook, Twitter and other ad/analytics vendors through URL query strings — no hacker required. That matters because the same addresses keep surfacing in outright compromises: the quiz app Wishbone lost 2.2M email addresses from an unprotected database years earlier, and an ad agency was later found with 150K+ personal records from user-filled forms sitting in an open database.
First-order effects
The named sites must scrub email parameters from outbound URLs and audit which vendors received them, while Facebook and Twitter are revealed as recipients of addresses users never knowingly shared with those platforms.
If query-string leakage is endemic, email hardens into a de facto cross-site identifier that follows users regardless of any single site's breach record, pushing regulators and browser/platform vendors toward stripping PII from URLs by default rather than relying on each site's diligence.
The trend: Email addresses are becoming a persistent cross-site identifier that leaks through everyday ad and analytics plumbing even when no database is ever breached.
Millions of email addresses were left exposed by companies like Quibi, JetBlue and Wish and passively collected by third party advertising and analytics companies like Google and Facebook, according to a new report. https://www.nytimes.com/...
People who downloaded the Quibi app were asked to submit their email addresses. Then they received a confirmation link. Clicking on the link made their email addresses available to Google, Facebook, Twitter and Snapchat. https://www.nytimes.com/...
Quibi, JetBlue and Others Gave Away Email Addresses, Report Says Personal data from millions of customers ended up with Google, Facebook and other trackers, making it easier for them to be tracked online and targeted with ads, according to a study. https://www.nytimes.com/...
Companies like Quibi, JetBlue and Wish allowed third-party trackers to grab millions of their customers' email addresses so that they could be targeted for ads. https://www.nytimes.com/...
The customers exposed their email addresses when signing up for apps, said the researcher that runs the digital strategy firm Victory Medium. In a report, he described the giveaway of personal data as part of a “sloppy and dangerous growth hack.” https://www.nytimes.com/...
Very detailed research and disclosure from @thezedwards on often overlooked privacy issues in ad tech. Lots of publishers impacted here, but I'm sure this is just the tip of the iceberg. Learn to spot these leaks and hold media companies accountable. https://twitter.com/...
There's a surprising level of fear-mongering in pieces like this with using words like “leak” or “hack”. Really wish there were more folks from ad-tech consulted/quoted. Sending an encoded email in a URL referer to the the FANG companies is a non-event. https://www.nytimes.com/..…