Google Shutters Google+ After It Exposed Data for Hundreds of Thousands of UsersThe company also didn't tell users about the exposure.

ByMallory Locklear

This story originally appeared onEngadget

Beck Diefenbach/Reuters via engadget

Google exposed private data from hundreds of thousands of Google+ users and then chose not to inform those affected by the issue. TheWall Street Journalreported that sources close to the matter claim the decision to keep the exposure under wraps was made among fears of regulatory scrutiny. Google said it discovered and immediately fixed the issue in March of this year.

According to theWall Street Journal'ssources as well as documents reviewed by the publication, a software vulnerability gave outside developers access to private Google+ user data between 2015 and 2018. And an internal memo noted that while there wasn't any evidence of misuse on behalf of developers, there wasn't a way to know for sure whether any misuse took place. Google said that it also found no evidence that any of the developers behind the 438 applications that used the API in question were aware of the bug. Exposed data included names, email addresses, birth dates, gender, profile photos, places lived, occupation and relationship status.

Though Google allows developers to collect Google+ profile information when granted access by users, a bug gave developers access to the profile data of friends of those users as well, regardless of whether those friends had chosen to share that information publicly. Google said in ablog postthat nearly 500,000 users may have been impacted, but because the company keeps the log data from this specific API for only two weeks at a time, it can't fully confirm who was truly impacted and who was not. The company noted that information like Google+ posts, messages and G Suite content weren't included in the exposure.

"Our Privacy and Data Protection Office reviewed this issue, looking at the type of data involved, whether we could accurately identify the users to inform, whether there was any evidence of misuse and whether there were any actions a developer or user could take in response. None of these thresholds were met in this instance," said Google. TheWall Street Journalreports that CEOSundar Pichaiwas notified of the plan to not disclose the data exposure and a document obtained by the publication warned that if it was indeed disclosed, it could result in "us coming into the spotlight alongside or even instead of Facebook despite having stayed under the radar throughout the Cambridge Analytica scandal."

In light of this issue, Google will be shutting down the consumer version of Google+ and will do so over the course of 10 months in order to allow users to transition out of the service. The company aims to complete that process by August of next year. Additionally, Google is giving users more control over the data they share with apps, will limit the apps that can receive permissionto access Gmail dataand will limit the ability of apps to retrieve call log and SMS access on Android.

While Pichaideclined to appearat a Senate Intelligence Committee hearing that touched on election meddling and security, hewill testifybefore the House Judiciary Committee next month and discuss bias, privacy and Google'srumored workin China.

Wavy Line

Editor's Pick

Related Topics

Business News

An 81-Year-Old Florida CEO Just Indicted for a $250 Million Ponzi Scheme Ran a Sprawling Senior Citizen Crime Ring

Carl Ruderman is the fifth senior citizen in the Miami-Fort-Lauderdale-Palm Beach metropolitan area to face charges in connection with the scam.

Resumes & Interviewing

This AI Resume Tool is Only $29.97 So You Can Make Job-Hunting Easier

Expand your growth potential with this back-to-school sale.

Living

How Spending Time Alone Has Transformed My Life

It's time to embrace the power of spending time alone.

Thought Leaders

So, You've Been Hacked. These are the Best Practices for Business Leaders Post-Hack

The lasting effects of a cyber incident can impact an organization's reputation, customers, workforce, databases and network architecture.