Twitter may have to pay hundreds of millions in fines for privacy screw-up

At issue is the 2019 revelation that Twitter used some users' phone numbers for advertising, even though they were submitted for security purposes.
 By 
Jack Morse
 on 
Twitter may have to pay hundreds of millions in fines for privacy screw-up
Oops! Credit: Vicky Leta / mashable

As far as mistakes go, Twitter's notorious two-factor authentication boondoggle could end being a costly one.

Buried deep inside the company's Monday 10Q filing with the Securities and Exchange Commission is a note that the social media giant might end up on the receiving end of up to $250 million in fines. At issue was Twitter "inadvertently" (it swears) using users' phone numbers for advertising from 2013 to 2019 — numbers that were only provided for security purposes. The Federal Trade Commission apparently didn't take kindly to that, and sent a draft complaint Twitter's way on July 28.

For those blessed to not remember every single Twitter privacy scandal, it's worth a reminder just how problematic the 2019 revelation that Twitter matched some users to advertisers' marketing lists based on their 2FA numbers actually was.

Specifically, privacy experts noted that using phone numbers volunteered for security reasons for advertising represents a fundamental betrayal of trust. And that betrayal comes with real consequences.

"Twitter 'unintentionally' used the information it got from you to secure your account in order to make money," Eva Galperin, the EFF's director of cybersecurity, wrote at the time. "This kind of behavior undermines people's willingness to use 2FA and makes them less secure in the long run."

It also, according to Twitter's Monday filing, might just so happen to violate the company's 2011 FTC consent order.

"In March 2011, to resolve an investigation into various incidents, we entered into a consent order with the FTC that, among other things, required us to establish an information security program designed to protect non-public consumer information and also requires that we obtain biennial independent security assessments," reads the 10Q filing. "[On] July 28, 2020, we received a draft complaint from the FTC alleging violations of the 2011 consent order with the FTC and the FTC Act."

SEE ALSO: Not even Jack Dorsey can figure out how to use Periscope

Twitter says the matter "remains unresolved," and estimates the "probable loss in this matter is $150.0 million to $250.0 million."

Whether such a fine would be enough to prevent similar privacy mistakes in the future is anyone's guess, but it would at least be a start.

Related Video: It's surprisingly easy to be more secure online

Mashable Image
Jack Morse

Professionally paranoid. Covering privacy, security, and all things cryptocurrency and blockchain from San Francisco.

Mashable Potato

Recommended For You
How hackers are stealing millions from ATMs, FBI warns
a card being inserted into an atm

UK fines porn company £1.35 million for lack of age checks
two naked people pixelated on computer with sensitive content notice blocking them

See Samsung Galaxy S26's Privacy Display feature in action
galaxy s25 ultra phone on display at galaxy unpacked launch event

Grok is producing millions of sexualized images of adults and children
A sign next to bus stop in London reads "Who the hell would want to use social media with a built-in child abuse tool?" and a photo of Elon Musk.

Samsung Galaxy S26 will have ‘pixel level’ privacy feature, Samsung confirms
Samsung Galaxy S25 from the rear

More in Tech
How to watch Chelsea vs. Port Vale online for free
Alejandro Garnacho of Chelsea reacts

How to watch 'Wuthering Heights' at home: Margot Robbie and Jacob Elordi's controversial romance now streaming
Margot Robbie and Jacob Elordi embracing in still from "Wuthering Heights"

How to watch New York Islanders vs. Philadelphia Flyers online for free
Matthew Schaefer of the New York Islanders warms up

How to watch Mexico vs. Belgium online for free
Israel Reyes of Mexico reacts

How to watch Brazil vs. Croatia online for free
Vinicius Junior #10 of Brazil leaves

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone


NYT Connections hints today: Clues, answers for April 2, 2026
Connections game on a smartphone

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!