The encyclopedia · Legal & Compliance · Legal decision · 2013–2022
Twitter reused 2FA phone numbers for ads — a $150M FTC penalty
Twitter told users their phone numbers secured their accounts — then matched them to advertisers. The FTC made it pay $150M.
Twitter · 2022-05-25
What happened
From 2013, Twitter asked users to supply a phone number or email address to improve account security — to reset passwords, unlock flagged accounts and enable two-factor authentication. The company told users this information would help secure their accounts, and nothing more.
From 2014 to 2019, more than 140 million users handed over their details. Twitter, however, failed to mention that it would also use the numbers and emails for targeted advertising, letting advertisers match the data against their own lists or data-broker information to serve specific ads to specific people.
On 25 May 2022, the FTC and the Department of Justice announced a proposed order requiring Twitter to pay a $150 million civil penalty. The FTC alleged the practice was deceptive and violated the FTC Act, the EU-U.S. and Swiss-U.S. Privacy Shield agreements, and a 2011 FTC order that separately barred Twitter from misrepresenting its privacy and security practices.
Beyond the fine, the order barred Twitter from profiting from the deceptively collected data, required it to notify affected users that their security data had also been used to target ads, and forced it to offer other multi-factor authentication options that do not depend on a phone number.
Why it happened
- Twitter treated data collected for security as a free advertising input, assuming users would not notice the reuse.
- It ignored an existing 2011 order that already prohibited misrepresenting how customer information was handled.
The lesson
Data collected for one purpose is not free for another — a security promise, broken, turns consent into a fine and a court order.
Aftermath
The $150 million penalty was among the largest the FTC had ever obtained at that point, and it highlighted the risk of reusing security data for advertising. The order forced Twitter to notify over 140 million users that their phone numbers and emails had been used to target ads, and to support authentication methods that do not require a phone number. For the industry, the case reinforced that a promise about how data will be used is a binding commitment, especially when a prior consent order is already on file.
Sources
- FTC Charges Twitter with Deceptively Using Account Security Data to Sell Targeted Ads — Federal Trade Commission
- Twitter Agrees with DOJ and FTC to Pay $150 Million Civil Penalty and Implement Comprehensive Compliance Measures — U.S. Department of Justice
spotted an error? The club wants to know.
More like this
Sony BMG put rootkits on 22 million music CDs and paid millions in settlements
Anthropic settled a $1.5B copyright lawsuit — the price of training AI on pirated books
Ross Intelligence trained its AI on Westlaw's headnotes — a court called it theft
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.