Twitter Used 2FA Phone Numbers to Sell Ads

Twitter fail whale.
(Image credit: Screenshot by Tom's Guide)

Twitter has issued a mea culpa for repurposing user information that was meant to be private in its advertising platforms.

In a statement this week, Twitter said that it had discovered instances of user phone numbers and email addresses being "inadvertently" used for its Tailored Audiences and Partner Audiences advertising platforms.

According to Twitter, the phone numbers and e-mail addresses were uploaded to its service for security features, like two-factor authentication (2FA), and shouldn't have been used in any way for advertising. 

But for an unidentified period of time, they were. Twitter said that it turned off the use of the personal information for ads on September 17.

Tailored Audiences is designed to let advertisers target their own customers who are already using Twitter. It does that by checking their own contact list information, such as e-mail addresses and phone numbers, against Twitter's userbase.

Partner Audiences is a similar service that targets Twitter users with ads, but relies on third-party data instead of the information an advertiser might have collected on its own.

Twitter said that it believes the personal information was shared after advertisers uploaded their own or third-party datasets of users to Twitter servers. The company --mistakenly, it says -- matched its own database of phone numbers and email addresses to those uploaded by advertisers, causing the "error." 

The problem, however, is that Twitter doesn't know whether your information was revealed or not. In its statement, the company said that it "cannot say with certainty how many people were impacted by this." It added, however, that information wasn't shared outside of Twitter's own platform.

Still, for affected users, there isn't much to do, other than hope it doesn't happen again. And Twitter said it's doing what it can to make sure it doesn't.

"We’re very sorry this happened and are taking steps to make sure we don’t make a mistake like this again," the company said.

Don't give up on 2FA

Unfortunately, Twitter requires that any user who wants to enable 2FA provide his or her mobile phone number to Twitter. That's whether or not the user wants to enable SMS-based 2FA, which does need the mobile number, or other 2FA methods such as authenticator apps or physical security keys, which don't use phone numbers. 

Other prominent online services, such as Google, don't require users to provide phone numbers to use non-SMS-based 2FA.

Any kind of 2FA is better than no 2FA at all, since 2FA is a very good safeguard against jerks hijacking your online accounts, even if they know your username and password. 

But SMS-based 2FA is the weakest form, because SMS messages can be intercepted and phone numbers can be stolen. Authenticator apps and physical security keys are much better.

TOPICS

Don Reisinger is CEO and founder of D2 Tech Agency. A communications strategist, consultant, and copywriter, Don has also written for many leading technology and business publications including CNET, Fortune Magazine, The New York Times, Forbes, Computerworld, Digital Trends, TechCrunch and Slashgear. He has also written for Tom's Guide for many years, contributing hundreds of articles on everything from phones to games to streaming and smart home.

Latest in Social Media
Elon Musk next to the X logo for the social media network that used to be called Twitter
X was down — live updates on outage Musk blames on ‘massive cyberattack’
Bluesky logo with X logo in the background
Flashes is a brand new Instagram alternative — and it’s basically Bluesky for images
Instagram app on iPhone
Instagram was down — live updates on the quick outage
elon musk in front of image of earth from space
Elon Musk reportedly exploring buying TikTok — Bytedance says 'pure fiction'
Instagram logo on iPhone with Instagram website in background.
Instagram now lets you schedule DMs — here's how to do it
TikTok displayed on a smart phone with a USA flag in the background
Google and Apple warned by Congress to be ready to remove TikTok from app stores — here's the date
Latest in News
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
half-life alyx
Latest Half-Life 3 rumors point to a 2025 release — and maybe pigs will fly