Elon Musk’s X has asked the U.S. Federal Trade Commission to terminate or substantially modify a May 2022 consent order that governs the company’s data security and privacy practices. The FTC has opened a 30-day public comment period on the petition, which would end oversight roughly 16 years early if granted. X argues the order applies to a corporate structure and personnel from the pre-acquisition Twitter era, imposes about $17 million in compliance costs, and diverts engineering resources from artificial intelligence development.
The 2022 order followed FTC findings that Twitter used phone numbers and email addresses collected for multifactor authentication to support personalized advertising, and it extended an earlier 2011 order imposed after two hacking incidents required the company to strengthen cybersecurity controls. X cited a 2024 California court dismissal of related class-action claims as support for its position that the disputed data use was permitted under Twitter’s terms, while acknowledging that a previous attempt to escape the order was rejected by a federal judge in 2023 on procedural or venue grounds.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The FTC said public comments on whether to revise or rescind X's 2022 consent order are due by July 2 before the agency decides next steps. The comment process concerns X's request to modify or set aside the order tied to Twitter's use of security data for advertising.
After receiving X's request, the FTC opened a 30-day public comment period on whether to end or modify the order governing the company's data security and privacy practices.
X asked the FTC to terminate or substantially modify the May 2022 consent order, arguing it applies to a company structure that no longer exists and imposes significant compliance costs.
In 2024, a California court dismissed a class action tied to Twitter's use of MFA phone numbers and email addresses for advertising, which X cites in support of its position.
A federal judge rejected X's earlier attempt to get out of the 2022 FTC order in November 2023, with the reports saying the decision was based on procedural or venue grounds.
In May 2022, the FTC issued a new consent order extending oversight after finding Twitter used phone numbers and email addresses collected for multifactor authentication to support personalized advertising.
The FTC issued a consent order in 2011 requiring Twitter to improve its cybersecurity after two hacking incidents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceftc.gov
Open sourceismg-cdn.nyc3.cdn.digitaloceanspaces.com
Open sourceismg-cdn.nyc3.cdn.digitaloceanspaces.com
Open sourceismg-cdn.nyc3.cdn.digitaloceanspaces.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.