Breach report
Social MediaGoogle (Alphabet)
Google Plus shutting down after security glitch exposes up to 500,000 users' data
Google shut down the consumer version of Google+ after revealing an API bug had exposed private profile data of up to 500,000 users to outside developers, and after reports it delayed disclosure to avoid regulatory scrutiny.
Reported by CBS News
Records exposed
500K
Up to 500,000 users (a second bug later affected 52.5 million)
Scale vs. largest on file
- When
- 2018 (bug existed 2015–2018)
- How they got in
- API bug exposing private profile fields to third-party apps
- Sector
- Social Media
On October 8, 2018, Google announced it would close the consumer version of its Google+ social network after an internal review found a software bug that had let third-party developers see profile information users had not made public. The flaw sat in a Google+ People API and had existed from 2015 until Google discovered and patched it in March 2018. Google said up to 500,000 accounts might have been affected and as many as 438 applications could have used the API during that window.
The exposed fields included names, email addresses, occupations, genders, ages and profile photos. Posts, messages, phone numbers and Google account data were not involved. Google said it found no evidence that developers were aware of or had misused the bug, but it also acknowledged that it kept API logs for only two weeks, so it could not say for certain what had happened before March.
The announcement came hours after The Wall Street Journal reported that Google had chosen not to disclose the problem when it was found, in part because of concerns it would draw regulatory attention and comparisons with Facebook's Cambridge Analytica scandal, which had broken that same month. Google said the incident did not meet its threshold for notifying users. Lawmakers pressed the company for answers, and Alphabet shares slipped on the news.
The situation worsened in December 2018, when Google disclosed a second Google+ API bug introduced in a November software update that exposed profile data of about 52.5 million users for six days. Google responded by moving the shutdown of consumer Google+ forward from August to April 2019 and cutting off developer API access sooner. A consumer class action over the exposures was later settled for $7.5 million.
Google framed the shutdown partly as a response to low engagement, but the incident became a case study in the risks of third-party API access and the reputational cost of delayed disclosure. Coming during a year of intense scrutiny of how tech platforms share user data with developers, it reinforced calls for clearer breach-notification rules and for companies to limit how much profile information outside apps can reach. For users, it was a reminder that data shared on a platform can be exposed through integrations they never directly interact with.