Twitter's former head of security has filed a formal whistleblower complaint detailing systemic security and privacy failures at the social media platform, raising national security concerns about the company's operational practices.
Peiter Zatko, who served as Twitter's security chief until August 2022, submitted his complaint to the Securities and Exchange Commission, the Federal Trade Commission, and Congress. Zatko's allegations center on Twitter's inadequate security infrastructure, insufficient logging of employee access to sensitive systems, and failure to properly track data breaches and security incidents. The complaint portrays a company that deprioritized security investments in favor of rapid feature development and cost reduction.
Among the specific allegations, Zatko claimed Twitter maintained inaccurate records of its user base, making it impossible to determine the true scale of bot accounts and fake users on the platform. This directly undermines Twitter's disclosures to investors about monthly active users. He also alleged the company failed to implement basic security hygiene practices, including multi-factor authentication requirements for employees accessing critical infrastructure. Zatko stated that foreign state actors and other threat groups likely exploited these gaps to gain unauthorized access to Twitter's systems.
The complaint documents instances where Twitter's data security team flagged critical vulnerabilities, only to have executives deprioritize fixes due to budget constraints. Zatko alleged the company knowingly allowed security debt to accumulate while executives publicly claimed otherwise. This pattern created conditions where malicious insiders could access sensitive user data without detection.
Zatko's claims carry weight given his background. Before Twitter, he worked at Google and maintained a reputation as a serious security researcher. His willingness to file formal complaints with regulators signals he possesses documentary evidence backing his assertions. The SEC and FTC have authority to investigate corporate misconduct affecting shareholders and consumers respectively. Congress's interest centers on whether Twitter poses national security risks, particularly regarding foreign surveillance or information warfare capabilities.
Twitter's response disputed the characterization of its security practices, stating the company invested heavily in security infrastructure and resolved issues identified by internal teams. The company argued Zatko's claims lacked context and misrepresented normal security operations.
The complaint carries implications across multiple regulatory domains. The FTC has authority to take action against companies making false claims about privacy protections. A confirmed pattern of security negligence could result in penalties, operational mandates, or enhanced oversight. Congress may use the complaint to inform legislation addressing social media accountability. For shareholders and advertisers, the allegations raise questions about data security representations made to investors.
The timeline matters. Zatko's departure occurred before Elon Musk's acquisition of Twitter in October 2022. This separation provides distance but also complicates assessment of whether conditions improved or worsened under new ownership. Musk subsequently eliminated much of Twitter's security team during cost-cutting measures, which may reinforce Zatko's original concerns about deprioritized security investments.
