Skip to main content

Twitter Apologizes for Using Your Phone Number for Advertising - By Sergiu Gatlan


Twitter says that some of its users' phone numbers and email addresses provided for account security like two-factor authentication may have been used accidentally for ad targeting.
"We recently discovered that when you provided an email address or phone number for safety or security purposes (for example, two-factor authentication) this data may have inadvertently been used for advertising purposes, specifically in our Tailored Audiences and Partner Audiences advertising system," says the company.
The information has been shared publicly since Twitter does not know the exact number of people that were affected in this incident and the company wanted to make everyone aware of what happened.

Issue addressed as of September 17

"No personal data was ever shared externally with our partners or any other third parties," added Twitter. "As of September 17, we have addressed the issue that allowed this to occur and are no longer using phone numbers or email addresses collected for safety or security purposes for advertising."
Twitter's Tailored Audiences is an advertising product designed to allow advertisers from all over the world to send targeted ads to customers they have in their marketing lists based on information such as phone numbers and email addresses.
The Partner Audiences advertising system, on the other hand, makes it possible for advertisers to target users from lists provided by third-party partners.
We’re very sorry this happened and are taking steps to make sure we don’t make a mistake like this again. - Twitter
"When an advertiser uploaded their marketing list, we may have matched people on Twitter to their list based on the email or phone number the Twitter account holder provided for safety and security purposes," states Twitter's apology statement.
The company apologized for this error and says that it's taking measures to make sure that a similar mistake will not happen again. Customers who want to ask for more info on this incident can contact Twitter's Office of Data Protection through this form.

Facebook's 2FA info mishap

Something similar happened last year when, as Gizmodo's Kashmir Hill discovered, Facebook built complex advertising profiles for all its users containing everything from their two-factor authentication phone numbers to info harvested from their friends' profiles.
Later on, Facebook used the phone numbers its users added for two-factor authentication as an additional targeting vector for various advertisers using its platform to deliver targeted ads.
This security mishap was subsequently discovered by a research team after the phone numbers added to test accounts were actively being targeted by advertisers after just a couple of weeks.
A Facebook spokesperson told Hill at the time that the company used "the information people provide to offer a better, more personalized experience on Facebook, including ads."
"We are clear about how we use the information we collect, including the contact information that people upload or add to their own accounts. You can manage and delete the contact information you've uploaded at any time."

Comments

Popular posts from this blog

Babuk ransomware is back, uses new version on corporate networks

  After announcing their exit from the ransomware business in favor of data theft extortion, the Babuk gang appears to have slipped back into their old habit of encrypting corporate networks. The criminals are currently using a new version of their file-encrypting malware and have moved the operation to a new leak site that lists a handful of victims. Gang’s still in the game The Babuk ransomware group became known at the beginning of the year but the gang says that their attacks had started in mid-October 2020, targeting companies across the world and demanding ransoms typically between $60,000 and $85,000 in bitcoin cryptocurrency. In some cases, victims were asked hundreds of thousands for data decryption. One of their most publicized victims is the Washinton DC’s Metropolitan Police Department (MPD). This attack likely pushed the threat actor into announcing its retirement from the ransomware business only to adopt another extortion model that did not include encryption....

Ransomware's Dangerous New Trick Is Double-Encrypting Your Data

  Ransomware groups have always taken a more-is-more approach . If a victim pays a ransom and then goes back to business as usual-hit them again. Or don’t just encrypt a target’s systems; steal their data first, so you can threaten to leak it if they don’t pay up. The latest escalation? Ransomware hackers who encrypt a victim’s data twice at the same time. Double-encryption attacks have happened before, usually stemming from two separate ransomware gangs compromising the same victim at the same time. But antivirus company Emsisoft says it is aware of dozens of incidents in which the same actor or group intentionally layers two types of ransomware on top of each other. “The groups are constantly trying to work out which strategies are best , which net them the most money for the least amount of effort,” says Emsisoft threat analyst Brett Callow. “So in this approach you have a single actor deploying two types of ransomware. The victim decrypts their data and discovers it’s not act...

Linux For Apple M1 Macs is Finally Here, Thanks To Corellium

  Just when we thought that Desktop/Notebooks on ARM chipsets doesn’t make any sense, Apple came up with a revolutionary chipset M1 and showed the world what it’s capable of. Unlike other Mac counterparts with Intel CPUs, M1 lacked the ability to run Linux, until yesterday. Thanks to Corellium, running Linux for M1 Macs is now possible. The company known for winning a lawsuit against Apple has finally created its own Linux OS for M1 Macs. This certainly opens doors for other Linux communities to do the same. Corellium’s Linux For M1 Macs Is In Early Beta Stages Creator of Linux, Linus Torvalds, wanted M1 Macbook Air to run Linux , and it’s finally a reality. Corellium’s CTO, Chris Wade, tweeted yesterday that Corellium’s Linux OS is available and is in very early beta stages. Adding to that, he also warned users to go ahead with the installation only if they know what they’re doing. More details about the “full release with USB” were supposed to be revealed today, but there’s ...