privacy-and-security

Google Plus Data Breach: What Happened and Why It Still Matters

The Google+ data breach refers to a series of security incidents affecting Google+ services, most notably a vulnerability present in the Google+ People API that exposed limited...

Mara Ellison
Google Plus Data Breach: What Happened and Why It Still Matters

What the Google+ Data Breach Was and Why It Matters

The Google+ data breach refers to a series of security incidents affecting Google+ services, most notably a vulnerability present in the Google+ People API that exposed limited public profile fields to apps without proper disclosure. Discovered in 2018 and disclosed to the public in October of that year, the exposure did not involve passwords, financial data, or private messages, but it did affect names, email addresses, occupations, ages, and other basic profile details. No major user reports of identity theft have been directly attributed to this incident, but it remains a significant event in how Google handled data disclosures, API permissions, and transparency.

Key Facts at a Glance

Attribute Verified Detail Source Type
Disclosure Date October 2018 Google's Transparency Report and company statements
API Involved People API (plus.people.get) Postmortem analyses and technical reports
Data Exposed Public profile fields: name, email, age, occupation, gender, and relationship status Google Cloud API documentation and disclosure notes
Accounts Affected Approximately 52.5 million profiles (varies by report) Google disclosures and regulatory filings
Exploitation Confirmed Limited evidence of automated collection by apps Industry security assessments

How the Google+ Exposure Happened

The central technical issue involved the Google+ People API, which allows apps to request basic profile fields when a user grants permission. A ‘circles’ visibility bug and overly broad default permissions meant some apps could access public profile information even when apps were not explicitly granted permission for those fields. Circa early 2018, a low-risk API change introduced a misconfiguration that persisted until late 2018, when Google identified and remediated it. No evidence suggests widespread exploitation, but the risk of automated scraping by apps existed while the flaw was live.

Technical Context Without Jargon

APIs are interfaces that let apps ask services like Google+ for data. Visibility settings control who can see each field (public, circles, private). A misconfigured API can return more data than intended when apps request access to what should be limited profile fields, creating a brief window where more information was surfaced than the owner intended.

What Data Was Actually Exposed

Only data that users had set to public on their Google+ profile could be retrieved, and the exposure was limited to basic profile attributes. Sensitive content such as private messages, direct messages, and payment information was not involved. The scale fluctuated in reports as Google refined its estimates, but the company confirmed millions of profiles were included during the period the bug was active.

Google's Disclosure and Timeline

Google discovered the issue internally in March 2018, conducted an investigation, and remediated the API behavior by late November 2018. Public disclosure followed in October 2018 alongside an update on Google+, which the company later announced would be shut down for consumers in 2019. Google stated it found no evidence of widespread misuse, though researchers noted that some apps might have collected data within the permitted scope before the fix. No material change to consumer accounts, balances, or stored content resulted from the exposure.

Implications for Privacy and Security Practices

The incident underscored how API permissions and visibility controls can interact in complex ways, prompting industry attention to default scopes and least-privilege access. For users, it reinforced the importance of periodically reviewing app permissions and profile visibility settings. For platforms, it highlighted the need for rigorous change management around APIs and clearer communication about what data is accessible to third parties.

How This Affects Users Today

Google+ for consumers was scheduled for shutdown well before the breach disclosures and was formally retired in 2019. Current risks tied to the 2018 exposure are low, as the underlying services are no longer active and the exposed fields were limited to public profile data. Users concerned about residual data should check connected apps and clear old authorizations on platforms where they still use social login features.

Quick Takeaways

  • The exposure involved public profile fields, not private messages or payment data.
  • Millions of profiles were potentially affected during the period the bug existed.
  • No evidence of widespread exploitation was confirmed by Google or external audits.
  • API permissions and visibility settings are key controls that influence what apps can access.
  • Reviewing connected apps and social login permissions remains a good periodic security habit.

Addressing Common Questions

Because Google+ is no longer active, most direct privacy impacts have faded. However, the event is useful as a case study in how platform APIs, permissions, and public visibility interact. It also illustrates the importance of timely disclosure and remediation by service providers when misconfigurations expose user information.

Related Reading

More pages in this topic cluster.

I Know Where Your Cat Lives: What It Is and Why It Matters for Privacy

I Know Where Your Cat Lives is a public demonstration built by artist and researcher Kenneth Lawler to illustrate how easily location data can be linked to everyday people and p...

Read next
Ashley Madison Sam: Profile, Notable Details, and Context

Ashley Madison Sam is commonly referenced in relation to the 2015 data breach of Ashley Madison, a website marketed to individuals seeking extramarital relationships. The userna...

Read next
The Secrets We Keep: A Comprehensive Exploration of Secrets, Their Impact, and Why We Hide Things

Secrets are ubiquitous yet rarely examined in depth. At their core, a secret is information intentionally withheld from others who might otherwise be affected by or entitled to...

Read next