Please ensure Javascript is enabled for purposes of website accessibility
Whistleblower Accuses Twitter of Cybersecurity Negligence
gvw_ap_news
By Associated Press
Published 3 years ago on
August 23, 2022

Share

 

A former head of security at Twitter alleged that the company misled regulators about its cybersecurity defenses, privacy protections and its ability to detect and root out fake accounts, according to a whistleblower complaint filed with U.S. officials.

The revelation could create serious legal and financial problems for the social media platform, which is currently attempting to force Tesla CEO Elon Musk to consummate his $44 billion offer to buy the company.

Peiter Zatko, Twitter’s security chief until he was fired early this year, filed complaints last month with the U.S. Securities and Exchange Commission, the Federal Trade Commission and the Department of Justice. The legal nonprofit Whistleblower Aid, which is working with Zatko, confirmed the authenticity of a redacted copy of the complaint posted online by the Washington Post.

Among Zatko’s most serious accusations is that Twitter violated the terms of a 2011 FTC settlement by falsely claiming that it had strong security measures in place to protect the security and privacy of its users. Zatko also accuses the company of deceptions involving its handling of “spam” or fake accounts, an allegation that is at the core of Musk’s attempt to back out of the Twitter takeover.

Shares of Twitter Inc. slid 5.4% Tuesday. Zatko didn’t immediately respond to a request for comment Tuesday. But he told the Post he “felt ethically bound” to come forward.

Better known by his hacker handle “Mudge,” Zatko is a highly respected cybersecurity expert who first gained prominence in the 1990s and later worked in senior positions at the Pentagon’s Defense Advanced Research Agency and Google.

He joined Twitter at the urging of then-CEO Jack Dorsey in late 2020, the same year the company suffered an embarrassing security breach involving hackers who broke into the Twitter accounts of world leaders, celebrities and tech moguls, including Musk, in an attempt to scam their followers out of bitcoin.

Twitter said in a prepared statement Tuesday that Zatko was fired for “ineffective leadership and poor performance” and said the “allegations and opportunistic timing appear designed to capture attention and inflict harm on Twitter, its customers and its shareholders.” The company called his complaint “a false narrative” that is “riddled with inconsistencies and inaccuracies and lacks important context.”

Zatko’s attorneys, Debra Katz and Alexis Ronickher, said Twitter’s claim about his poor performance is false and that he repeatedly raised concerns about “grossly inadequate information security systems” with top executives and Twitter’s board of directors. The lawyers said that in late 2021, after the board was given “whitewashed” information about those security problems, Zatko escalated his concerns, “clashed” with CEO Parag Agrawal and board member Omid Kordestani and was fired two weeks later.

The 84-page complaint describes a broken corporate culture at Twitter that lacked effective leadership and where Zatko said top executives practiced “deliberate ignorance” of pressing problems. His description of Dorsey’s leadership style is particularly scathing, saying the Twitter founder was “extremely disengaged” during the last months of his tenure as CEO to the point where he would not even speak during meetings on complex issues facing the company.

Zatko said he heard from colleagues that Dorsey would remain silent for “days or weeks.” Dorsey announced he was stepping down as Twitter CEO in November 2021.

The disclosure says Twitter offered no monetary incentives for improving security and platform integrity, although the company did offer $10 million bonuses last year for top executives who could generate short-term user growth.

Among Zatko’s damning accusations of cybersecurity malpractice: Software and security updates were disabled on more than a third of employees’ computers — unduly exposing them to malware — and it was common for people to install “whatever software they wanted on their work systems.” Such lapses are typically considered cardinal sins in cybersecurity.

Whistleblower Aid said it is legally precluded from sharing Zatko’s statement. The same group worked with former Facebook employee Frances Haugen, who testified to Congress last year after leaking internal documents and accusing the social media giant of choosing profit over safety.

A spokesperson for the U.S. Senate’s intelligence committee, Rachel Cohen, said the committee has received Zatko’s complaint and “is in the process of setting up a meeting to discuss the allegations in further detail. We take this matter seriously.”

Sen. Dick Durbin, an Illinois Democrat, said in a prepared statement that if the claims are accurate, “they may show dangerous data privacy and security risks for Twitter users around the world.”

Among the most alarming complaints is Zatko’s allegation that Twitter knowingly allowed the Indian government to place its agents on the company payroll where they had “direct unsupervised access to the company’s systems and user data.”

A 2011 FTC complaint noted that Twitter’s systems were full of highly sensitive data that could allow a hostile government to find precise location data for specific users and target them for violence or arrest. Earlier this month, a former Twitter employee was found guilty after a trial in California of passing along sensitive Twitter user data to royal family members in Saudi Arabia in exchange for bribes.

The complaint said Twitter was also heavily reliant on funding by Chinese entities and that there were concerns within Twitter that the company was providing information to those entities that would enable them to learn the identify and sensitive information of Chinese users who secretly use Twitter, which is officially banned in China.

Zatko also describes “deliberate ignorance” by Twitter executives on counting the millions of accounts that are automated “spam bots” or otherwise have no value to advertisers because there is no person behind them.

Alex Spiro, an attorney representing Musk in his effort to back out of his Twitter acquisition deal, said lawyers have issued a subpoena for Zatko. “We found his exit and that of other key employees curious in light of what we have been finding,” Spiro wrote in an email Tuesday. Spiro said Zatko and Musk have not been in contact at any time this year.

RELATED TOPICS:

DON'T MISS

What to Watch in Tuesday’s Big Elections in Wisconsin and Florida

DON'T MISS

Major Layoffs Begin at Health Agencies That Track Disease and Regulate Food

DON'T MISS

New Jersey Sen. Cory Booker Speaks Through the Night to Protest Trump’s Agenda

DON'T MISS

Trump Administration Sued Over Decision to Rescind Billions in Health Funding

DON'T MISS

Your Bag’s Hidden Journey From Check-In to Plane

DON'T MISS

Stock Market Today: Wall Street Dips, and Asia and Europe Recover a Bit

DON'T MISS

Israel Strikes a Building in Southern Beirut, Killing at Least 4 People

DON'T MISS

February US Job Openings Slip to 7.6M, Consistent With a Healthy but Decelerating Job Market

DON'T MISS

Braves’ Jurickson Profar Hit With 80-Game PED Ban

DON'T MISS

Watch: City Demolishes Historic Chinatown Building to Make Way for Housing

UP NEXT

Elon Musk Sells X to His Own xAI for $33 Billion in All-Stock Deal

UP NEXT

Trump Pledges US Aid for Asia Quake Despite Former Official Saying System in ‘Shambles’

UP NEXT

Vance and Wife Tour US Military Base in Greenland After Diplomatic Spat

UP NEXT

Middle East Latest: Israeli Strikes Kill a Family of 6 and a Hamas Spokesman in Gaza

UP NEXT

Alleged Leader of MS-13 Street Gang on the East Coast Is Arrested in Virginia

UP NEXT

Judge Allows Newspaper Copyright Lawsuit Against OpenAI to Proceed

UP NEXT

Middle East Latest: Israeli Military Orders Evacuation of Parts of Gaza City

UP NEXT

US Could Run Out of Money to Pay Its Bills by August Without a Debt Limit Deal, CBO Says

UP NEXT

The Atlantic Releases Entire Signal Chat Showing Hegseth’s Attack Plans Against Houthis

UP NEXT

Napster Sold to Tech Commerce Company for $207 Million

Trump Administration Sued Over Decision to Rescind Billions in Health Funding

21 minutes ago

Your Bag’s Hidden Journey From Check-In to Plane

24 minutes ago

Stock Market Today: Wall Street Dips, and Asia and Europe Recover a Bit

30 minutes ago

Israel Strikes a Building in Southern Beirut, Killing at Least 4 People

33 minutes ago

February US Job Openings Slip to 7.6M, Consistent With a Healthy but Decelerating Job Market

38 minutes ago

Braves’ Jurickson Profar Hit With 80-Game PED Ban

15 hours ago

Watch: City Demolishes Historic Chinatown Building to Make Way for Housing

15 hours ago

The Mystery of Melania Trump’s Wedding Dress and an eBay Sale

16 hours ago

Heading to Sierra? Prepare for Heavy Snow

16 hours ago

Mexican National Caught in Fresno County Pleads Guilty to Fentanyl Trafficking

16 hours ago

What to Watch in Tuesday’s Big Elections in Wisconsin and Florida

MADISON, Wis. — Two states nearly 1,000 miles apart will on Tuesday provide the best evidence yet of whether President Donald Trump and his ...

4 minutes ago

Elon Musk with a check for $1 million as he headlines a rally in support of conservative judicial candidate Brad Schimel in Green Bay, Wis., March 30, 2025. Elon Musk and groups tied to him have spent more than $25 million backing Schimel, the conservative candidate for the open court seat. (Jim Vondruska/The New York Times)
4 minutes ago

What to Watch in Tuesday’s Big Elections in Wisconsin and Florida

The Food and Drug Administration’s campus in White Oak, Md., Oct. 31, 2024. Hundreds of federal health workers, including doctors in senior leadership positions, began hearing on April 1, 2025 that they are losing their jobs. (Andrew Mangum/The New York Times)
10 minutes ago

Major Layoffs Begin at Health Agencies That Track Disease and Regulate Food

In this image provided by Senate Television, Sen, Cory Booker, D-N.J. speaks on the Senate floor, Tuesday morning, April 1, 2025. (Senate Television via AP)
14 minutes ago

New Jersey Sen. Cory Booker Speaks Through the Night to Protest Trump’s Agenda

People gather for a candlelight vigil in support of the Centers for Disease Control and Prevention in front of its headquarters in Atlanta, Friday, March 28, 2025. (AP/Ben Gray)
21 minutes ago

Trump Administration Sued Over Decision to Rescind Billions in Health Funding

A ramp agent loads bags into a plane’s cargo hold at LaGuardia Airport in New York, Jan. 23, 2025. The number of bags that can fit depends on the type of plane and on stacking strategy, like a game of Tetris. (Graham Dickie/The New York Times)
24 minutes ago

Your Bag’s Hidden Journey From Check-In to Plane

Wall Street street sign
30 minutes ago

Stock Market Today: Wall Street Dips, and Asia and Europe Recover a Bit

Damaged apartments building are seen after being struck earlier by an Israeli targeted attack in Dahiyeh, a southern suburb of Beirut, Lebanon, early Tuesday, April 1, 2025. (AP/Hussein Malla)
33 minutes ago

Israel Strikes a Building in Southern Beirut, Killing at Least 4 People

Pedestrians walk past a help wanted sign posted on the door of a restaurant in San Francisco, Tuesday, April 18, 2023. (AP File)
38 minutes ago

February US Job Openings Slip to 7.6M, Consistent With a Healthy but Decelerating Job Market

Help continue the work that gets you the news that matters most.

Search

Send this to a friend