/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Researcher: major sites like Wish and Mailchimp were leaking email addresses to ads and analytics companies including Facebook and Twitter via URL query strings

Breaches have been found on websites including Wish.com, JetBlue.com, Quibi.com, WashingtonPost.com, NGPVan.com and numerous other organizations...

Zach Edwards

Context & Ripple Effects

Zach Edwards' finding shifts the email-exposure story from breaches to plumbing: Wish, Mailchimp, JetBlue, Quibi, the Washington Post and NGPVan were passing user email addresses to Facebook, Twitter and other ad/analytics vendors through URL query strings — no hacker required. That matters because the same addresses keep surfacing in outright compromises: the quiz app Wishbone lost 2.2M email addresses from an unprotected database years earlier, and an ad agency was later found with 150K+ personal records from user-filled forms sitting in an open database.

First-order effects

  • The named sites must scrub email parameters from outbound URLs and audit which vendors received them, while Facebook and Twitter are revealed as recipients of addresses users never knowingly shared with those platforms.

Second-order effects

Third-order effects

  • If query-string leakage is endemic, email hardens into a de facto cross-site identifier that follows users regardless of any single site's breach record, pushing regulators and browser/platform vendors toward stripping PII from URLs by default rather than relying on each site's diligence.

The trend: Email addresses are becoming a persistent cross-site identifier that leaks through everyday ad and analytics plumbing even when no database is ever breached.

Discussion

  • @tiffkhsu Tiffany Hsu on x
    Millions of email addresses were left exposed by companies like Quibi, JetBlue and Wish and passively collected by third party advertising and analytics companies like Google and Facebook, according to a new report. https://www.nytimes.com/...
  • @nytimesbusiness @nytimesbusiness on x
    People who downloaded the Quibi app were asked to submit their email addresses. Then they received a confirmation link. Clicking on the link made their email addresses available to Google, Facebook, Twitter and Snapchat. https://www.nytimes.com/...
  • @devindra Devindra Hardawar on x
    Can Quibi do anything right https://twitter.com/...
  • @yashar Yashar Ali on x
    Quibi, JetBlue and Others Gave Away Email Addresses, Report Says Personal data from millions of customers ended up with Google, Facebook and other trackers, making it easier for them to be tracked online and targeted with ads, according to a study. https://www.nytimes.com/...
  • @matthewfederman Matthew Federman on x
    I expected this from the others, but you Quibi? You were supposed to change everything. https://twitter.com/...
  • @nytimesbusiness @nytimesbusiness on x
    Companies like Quibi, JetBlue and Wish allowed third-party trackers to grab millions of their customers' email addresses so that they could be targeted for ads. https://www.nytimes.com/...
  • @nytmedia @nytmedia on x
    The customers exposed their email addresses when signing up for apps, said the researcher that runs the digital strategy firm Victory Medium. In a report, he described the giveaway of personal data as part of a “sloppy and dangerous growth hack.” https://www.nytimes.com/...
  • @eliyastein Eliya Stein on x
    Very detailed research and disclosure from @thezedwards on often overlooked privacy issues in ad tech. Lots of publishers impacted here, but I'm sure this is just the tip of the iceberg. Learn to spot these leaks and hold media companies accountable. https://twitter.com/...
  • @profjeffjarviss @profjeffjarviss on x
    Looks very bad: Quibi gave away its entire database of 75 email addresses. https://twitter.com/...
  • @sriramk Sriram Krishnan on x
    There's a surprising level of fear-mongering in pieces like this with using words like “leak” or “hack”. Really wish there were more folks from ad-tech consulted/quoted. Sending an encoded email in a URL referer to the the FANG companies is a non-event. https://www.nytimes.com/..…