Supply chain ⛓ Supply Chain

Facebook and Twitter Third-Party Breach (November 2019)

📅 2019-11-01 🏢 One Audience
Primary Source ↗

Incident Details

Facebook & Twitter suffer data breach via third-party developers. On Monday, both Facebook and Twitter announced that the data of hundreds of users had been compromised due to a software development kit (SDK) named “One Audience” giving third-party developers access to certain data. The data includes email addresses, usernames and recent tweets of anyone who accessed certain apps including Giant Square and Photofy from their Twitter accounts. While Twitter has confirmed that the SDK was used for accessing the data of Twitter users on Android , they claim that no evidence has been seen for the same occurring on iOS. Third-party company: One Audience.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
One Audience
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2019-11-01 Breach occurred
  2. 2019-11-27 Publicly disclosed