Twitter bug that made your private tweets public went unnoticed for over 4 years

Some Twitter for Android users' accounts could have been impacted.
Twitter bug that made your private tweets public went unnoticed for over 4 years
A security flaw that affected "protected" Twitter accounts has finally been fixed. Credit: Aytac Unal/Anadolu Agency/Getty Images

Twitter users with an Android device should double- check their accounts, especially if they sent a tweet sometime between 2014 and 2019.

In a statement posted on the Twitter help forum on Thursday, the social network disclosed details surrounding a privacy bug that affected Twitter for Android users with protected tweets.

According to Twitter, if a user enabled “Protect your Tweets” in their settings, used the Twitter for Android app, and made other updates to their account settings, it’s possible that the protected tweets setting was disabled without users' knowledge. One example provided by Twitter of an account settings change that could have triggered the bug is a change to an account’s email address.

Twitter says the security flaw affected Android for Twitter users between Nov. 3, 2014 and Jan. 14, 2019. Twitter for iOS and web users were not impacted by the issue.

In its disclosure, the company said they reached out to users whose settings were changed due to the bug. However, Twitter is urging all Twitter for Android users to check their settings, as the company cannot confirm every account that the privacy flaw affected.

In a statement to Mashable, Twitter clarified that the users who could be affected would have had to change their settings (such as the account's email) within Twitter for Android.

The protected tweets feature allows users to lock down their Twitter accounts to the public. The user’s tweets are only shown to the account’s followers. Those who try to follow the account must first be approved by the user. Accounts with protected tweets cannot be retweeted. The now-fixed protected tweets issue would have made a user’s tweets publicly visible and allow any user to retweet or follow the account.

The timing of the bug's discovery could not have come at a more inopportune time for Twitter. The company is already under investigation for General Data Protection Regulation (GDPR) violations. The sweeping EU privacy law gives its citizens the right to request their personal data from companies. When Twitter turned down a request from a researcher looking for data related to the service’s short URL, the Irish Data Protection Commission (DPC) opened an investigation.

The DPC is aware of this Twitter for Android privacy issue, according to Bloomberg. Officials are currently looking into the matter and have not yet opened a second investigation into the company.

Under the GDPR, a company violating the law can face fines of up to 4 percent of its annual revenue. Twitter last reported $758 million in revenue during the third quarter of 2018 alone.

Mashable Potato

Recommended For You
Siri bug reportedly delays Apple's smart home lineup
By Jack Dawes
Apple's New HomePod Now Available Within Its Stores

SpaceX may be going public with a big fundraising target
A SpaceX Falcon Heavy rocket lifting off, next to a building bearing the SpaceX logo.

Updating your security mindset: Keep your data private and your devices secure
By PCMag
Cyber Security

Watch a real supernova blast evolve over 25 years in new telescope video
Chandra X-ray Observatory watching a supernova unfold


More in Tech
The Shark FlexStyle is our favorite Dyson Airwrap dupe, and it's $160 off at Amazon right now
The Shark FlexStyle Air Styling & Drying System against a colorful background.

Amazon's sister site is having a one-day sale, and this Bissell TurboClean deal is too good to skip
A woman using the Bissell TurboClean Cordless Hard Floor Cleaner Mop and Lightweight Wet/Dry Vacuum.

The best smartwatch you've never heard of is on sale for less than $50
Nothing CMF Watch 3 Pro in light green with blue and green abstract background

Reddit r/all takes another step into the grave
Reddit logo on phone screen

Take back your screen from ads and trackers with this $16 tool
AdGuard Family Plan: Lifetime Subscription

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.


Google launches Gemma 4, a new open-source model: How to try it
Google Gemma
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!