/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Sources say Apple and Meta gave user data to hackers in response to forged Emergency Data Requests; Discord said it had also fulfilled a forged legal request

Apple Inc. and Meta Platforms Inc., the parent company of Facebook, provided customer data to hackers who masqueraded as law enforcement officials …

Bloomberg William Turton

Context & Ripple Effects

Apple, Meta and Discord are shown as vulnerable to impersonated law-enforcement demands, turning an emergency-disclosure process into a route for attackers to obtain customer information. Related reporting later connected data obtained through fake legal requests to harassment of women and sexual extortion of minors, raising the stakes beyond a procedural failure.

First-order effects

  • Apple and Meta disclosed customer data to hackers posing as law-enforcement officials, while Discord says it fulfilled a forged legal request with the same result.
  • The affected users face exposure through data released under an emergency process intended for legitimate official requests.

Second-order effects

  • The reported misuse gives attackers information that related coverage says was used for harassment and sexual extortion, making verification of urgent requests a user-safety issue for the platforms rather than solely a law-enforcement operations issue.

Third-order effects

  • Emergency legal-request channels risk becoming a persistent social-engineering attack surface: platforms that prioritize rapid disclosure must balance that speed against stronger authentication of requesting agencies.

The trend: The episode is part of a broader shift in which the security of data-sharing systems depends as much on verifying institutional requesters as on protecting the data itself.

Discussion

  • @thegrugq @thegrugq on x
    One thing that @networkattack points out is that anything that can be done by authorised users can be done by hackers abusing authorised users' access. https://twitter.com/...
  • @alexstamos Alex Stamos on x
    @d1gi Probably. I know the FB LERT team has a huge challenge getting thousands of LE agencies to setup accounts, and if an EDR came from a real LE domain (with DKIM and everything) and looked legit they would likely respond.
  • @tiffanycli Tiffany C. Li on x
    Yes, the emails from Legal are annoying, and the trainings from IT/Security are annoying. But do them! Every single person in an organization has a role to play in protecting privacy and cybersecurity. Including the junior staff, who sometimes know what they are doing ;)
  • @cherthedev Cher Scarlett on x
    Maybe if Apple's investigations team spent their time investigating emergency requests instead of investigating workplace activists under false pretenses, they'd not be putting all of our privacy in jeopardy.
  • @cherthedev Cher Scarlett on x
    Literally everyone should be concerned that “emergency requests” don't require a court order, and that companies with a large volume of former law enforcement agents as employees not only don't have to call to verify requests, but cannot discern a real request from a fake one.
  • @tiffanycli Tiffany C. Li on x
    As someone who once was the junior legal/compliance person dealing with these requests, I was taught to always independently verify anything that looked like a government request for data. Call the agency yourself from a publicly-listed number, and so forth. Escalate up.
  • @cherthedev Cher Scarlett on x
    When we look critically at @Apple, @Meta, @Google, @yandexcom and other tech giants for their data collection, ESPECIALLY when it comes to government compliance, this is one of the major concerns we have as industry experts. https://www.bloomberg.com/...
  • @inteltechniques Michael Bazzell on x
    This sounds suspiciously similar to a scene I wrote for Mr. Robot. I am surprised it took this long to surface in real life. https://twitter.com/...
  • @moonalice Roger McNamee on x
    We are drowning in evidence of the internet's vulnerability to criminal and harmful behavior. Add this story — about hackers forging legal requests to misappropriate personal data from Apple and FB — to the list. https://twitter.com/...
  • @cherthedev Cher Scarlett on x
    Corporations like @Apple and @Meta should not be the deciding factor in public safety. We should be keenly aware and highly alarmed that these corporations have more control over our privacy and security than law enforcement and the government. https://www.protocol.com/...
  • @d1gi Jonathan Albright on x
    @alexstamos If the same thing happened to multiple (at least two major companies at this point) parties, it is probably the latter - right?
  • @tiffanycli Tiffany C. Li on x
    Any company that reaches a certain size or deals with a certain amount of user data is going to receive government requests for said data. You've got to have policies and workflows in place for this. Apple and Meta certainly did.
  • @tiffanycli Tiffany C. Li on x
    If you've ever found legal or security compliance obligations annoying and burdensome, remember that the consequence of not securing your data is something like this: a high-profile breach that lands your company in legal, financial, and PR trouble. https://twitter.com/...
  • @tiffanycli Tiffany C. Li on x
    W/o going into details, my worst experiences w/gov requests have come from both external and internal parties. Complaints that verification was unnecessary, time was of the essence, why even bother for a minor ask, Google and other big companies do it much faster, etc.
  • @alexstamos Alex Stamos on x
    @d1gi Facebook has a law enforcement portal with dedicated identities specifically for this reason, so it would be interesting to hear if these requests still came into email or if they took over those accounts.
  • @d1gi Jonathan Albright on x
    “...sent from from comprised law enforcement systems?” Fair's fair; this fact makes it a different story, and the headline above is a little misleading https://t.co/W1aAqBwKKL
  • @sarahfrier Sarah Frier on x
    One of the most tragic things about this hacker tactic: law enforcement has this pathway for data from companies in order to save lives/get to someone in immediate danger in extreme circumstances. But you definitely don't want these details in the wrong hands. https://twitter.com…
  • @evacide Eva on x
    Who fell for those fake emergency data requests from compromised law enforcement related accounts? Apple and Meta. https://twitter.com/...
  • @pathedger18 Patrick Hedger on x
    Hmmm maybe federal privacy legislation is a better idea than bills that would allow nefarious actors to demand customer data without needing to forge anything. Crazy idea, I know. https://twitter.com/...
  • @incilin Insanul Ahmed on x
    Umm this is not great https://twitter.com/...
  • @tonyromm Tony Romm on x
    hmm you know might not be great ! https://twitter.com/...
  • @sarahfrier Sarah Frier on x
    Once they'd hacked law enforcement email accounts, the hackers forged emergency requests to Apple, Meta, etc for user data. Once they had the target's address/details, they could then harass them (swatting, for instance) or bypass account security on their $$. https://twitter.com…
  • @josheidelson Josh Eidelson on x
    “Apple Inc. and Meta Platforms Inc., the parent company of Facebook, provided customer data to hackers who masqueraded as law enforcement officials” https://www.bloomberg.com/... @WilliamTurton
  • @rhinosoros Dwight Rhinosoros on x
    Jfc https://www.bloomberg.com/...
  • @briankrebs @briankrebs on x
    Crooks are now hacking police, govt email accounts/websites to send fake “emergency data requests” to wireless providers, ISPs, social media firms. The requests claim it's a matter of life & death, can't wait for subpoena. The compliance rate is high. https://krebsonsecurity.com/…
  • @josephfcox Joseph Cox on x
    Here is also a case where a scammer created a fake domain for a law enforcement task force to trick a telecom into providing location data without a warrant: https://www.vice.com/... https://twitter.com/...
  • @michaelguimarin Michael Guimarin on x
    This is why many of us have been against any kind of special access/rights for law enforcement since Clipper. Yes it makes the job harder, but the trade off is worth it. https://twitter.com/...