Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

Threads, just another social media platform or a hacker’s dream?

Threads-just-another-social-media-platform-or-a-hackers-dream

Social media platforms have fundamentally changed how we communicate, share experiences, and maintain relationships. On July 6, 2023, Meta, the parent company behind Facebook and Instagram, launched Threads, a text-based microblogging platform integrated with Instagram. The app amassed over 100 million users within its first week. Threads is designed as a text-focused platform for sharing updates and joining public conversations, positioned as a direct competitor to Twitter. However, the security and privacy concerns that Threads raises are substantial: according to its App Store privacy disclosure, Threads can collect health information, financial data, contacts, browsing and search history, location data, and purchases, among a wide range of other personal information. For anyone concerned about data privacy, Threads functions less like a neutral social platform and more like a comprehensive personal data collection system. The recommended action: if you use Threads, immediately enable two-factor authentication, restrict all sensitive app permissions at the device level, use a strong unique password, and avoid sharing sensitive personal information on the platform. For the broader context of data privacy and encryption, see Data Privacy Laws Driving the Need for Encryption and Data Security vs Data Privacy.

Quick Answer: Is Threads a Security Risk?

Threads is not simply another social media platform from a security perspective. The breadth of personal data it collects, including health, financial, location, browsing history, device signals, and sensitive information, combined with Meta’s history of data sharing across its platforms, creates a risk profile that most users do not fully understand when they sign up. The platform is not inherently malicious, but the concentrated data aggregation it enables creates a high-value target for attackers, and the sensitive categories of data it collects carry risks that extend beyond advertising exposure to identity theft, physical surveillance, and targeted social engineering. Users who understand this risk can take specific protective steps; users who do not are providing significantly more personal information than they may realize.

How Did Threads Gain Popularity?

Threads gained popularity extremely quickly because it is integrated with Instagram, which has over 500 million daily active users globally. Creating a Threads account requires only an Instagram account, eliminating the registration friction that normally limits new platform adoption. Instagram is primarily a photo and video sharing app; the text-based microblogging format of Threads offered something different for the existing Instagram user base. The ability to seamlessly share content between the two apps made the transition to Threads low-effort for Instagram users. The curiosity of trying something different, combined with the context of widespread dissatisfaction with Twitter at the time of Threads’ launch in July 2023, contributed to the rapid user growth that saw the app surpass a million users within an hour and 100 million users within its first week of availability.

Privacy Concerns Regarding Threads

This app raised privacy concerns about the information it stores almost immediately after launch. According to its App Store privacy disclosure, Threads can collect a wide range of personal information including health and fitness information, financial information, contacts, browsing and search history, location data, purchases, and what the disclosure categorizes as sensitive information. The specificity and quantity of data that Threads can access creates risk for the vast majority of users if that data is misused through targeting, sold to third parties, or accessed by attackers through a data breach.

Threads App Store privacy disclosure showing categories of personal data collected including health, financial, and location information
Threads App Store Privacy Disclosure: Categories of Personal Data Collected

Threads operates under Meta’s broader privacy policy, which also applies to Facebook and Instagram. This policy describes how Meta collects information on everything users do on its platforms: creating accounts, clicking or liking content, making online connections, and the devices used to access its products. It also covers activity on the device level, including whether an app is running in the foreground, whether a mouse is moving, messages sent and received, and purchase information including credit card details.

How Meta Collects Data and Its Privacy Policy

  • The launch of Threads in the European Union was initially delayed because of questions about how Meta handles user data and shares it across different platforms. Threads launched in the EU in December 2023 after Meta made commitments to EU regulators about data handling compliance with the Digital Markets Act (DMA) and General Data Protection Regulation (GDPR).
  • Many of the privacy issues with Threads stem from Meta’s past data practices and the lack of granular transparency about how Threads data is specifically used relative to data from Facebook and Instagram. Meta’s privacy policy applies to all three platforms, and the cross-platform data combination creates profiles far more comprehensive than any individual platform’s data alone.
  • The platform provides Meta with information regarding the posts users interact with and the people they follow. Threads’ privacy policy includes the types of content users view or interact with and how they interact with it, as well as how frequently and for how long they use Threads.
  • Meta’s privacy policy states that in addition to Threads activity, it has access to GPS position, cameras, photographs, IP information, device type, and device signals including Bluetooth signals, nearby Wi-Fi access points, beacons, and cell towers. When combined, this data can create an intricate and detailed map of a person’s physical movements and social connections, especially when cross-referenced with data already collected from Facebook and Instagram.
  • The primary stated commercial purpose for this data collection is advertising. While Threads does not display ads in its initial form, Meta has indicated it intends to introduce advertising to the platform. Data collected through Threads can also be used as part of Meta’s broader data collection to inform ad targeting on its other platforms.
  • As of the time of writing, data collected through Threads can be used as part of Meta’s larger data collection that informs advertising across its platform family.
  • Sensitive data categories that Threads may collect and that can potentially be shared with third parties include race, ethnicity, sexual orientation, biometric data, pregnancy status, political beliefs, and religious beliefs. If data in these categories reaches unauthorized recipients, the consequences can include targeted harassment, discrimination, and in extreme cases, physical harm. The breadth of data the app accesses creates significant value for any attacker who gains unauthorized access to it.

Tailored Encryption Services

We assess, strategize & implement encryption strategies and solutions.

How Is It Affecting Individuals?

Many individuals question the need to be concerned about social media companies accessing their data, particularly if they are not high-profile and do not use social media for controversial activities. The risk does not require individual targeting to be real: data collected at scale for advertising purposes is stored in systems that are themselves targets for attackers, and a breach of that data affects every user whose information was collected. The value of aggregated personal data is so much greater than the sum of individual profiles that the people whose data is collected effectively become the product, with their preferences, behaviors, and relationships monetized in ways they never explicitly consented to. The history of previous social platform incidents demonstrates that this is not a theoretical concern; users who believed their data was only used for advertising have had that data exposed in ways that enabled financial fraud, targeted harassment, and privacy violations. It is necessary to consider a platform’s history of how it has handled sensitive information when evaluating whether to use it and how much information to share.

Mitigating the Risks: Practical Steps for Threads Users

Users can take specific steps to reduce their exposure to the security and privacy risks that Threads presents:

  • Enable Two-Factor Authentication (2FA)

    Activate two-factor authentication on your Threads and connected Instagram accounts immediately. Use an authenticator app rather than SMS-based 2FA where possible, as SMS-based 2FA is vulnerable to SIM swapping attacks. 2FA prevents account takeover even if your password is compromised through a breach of another service you use.

  • Restrict App Permissions at the Device Level

    Review and restrict Threads’ device permissions in your phone’s settings. Limit location access to ‘While Using App’ or ‘Never’; restrict camera and microphone access if not required for your specific use of the platform. These permissions feed directly into the location and behavioral data collection described in the privacy disclosure.

  • Use Strong, Unique Passwords

    Create a strong, unique password for your Threads account that is not reused from any other service. A password manager helps generate and store unique passwords per service. If your Threads password is also used for email, banking, or other sensitive services, a breach of any one of those services could lead to account takeover on all of them.

  • Practice Mindful Sharing

    Be deliberate about what personal, health, financial, or location information you share on the platform through your posts or in your profile. Information shared publicly on Threads is stored, indexed, and potentially cross-referenced with other data; information that appears innocuous in isolation can become sensitive when combined with other data in a profile.

  • Manage Your Audience and Content Access

    Regularly review privacy settings within the Threads app to control who can see your content and interact with it. Limit the audience for sensitive content to trusted individuals only, and periodically review your followers and following lists to ensure only trusted individuals can access your shared content.

  • Keep the App and Device Updated

    Keep the Threads app and your device’s operating system up-to-date to benefit from security patches that address vulnerabilities discovered after launch. This is particularly important for new platforms: security researchers actively scrutinize new apps after launch and may identify vulnerabilities not caught during development.

Privacy Risk Assessment: Threads Data Categories

Data Category CollectedRisk If Breached or MisusedProtective Action
Health and fitness informationInsurance discrimination, targeted healthcare fraud, physical vulnerability exposureDo not share health information on the platform; restrict permissions that could infer health status
Financial informationFinancial fraud, identity theft, account takeoverDo not share financial details; do not link payment information beyond what is necessary
Precise location (GPS)Physical surveillance, stalking, pattern-of-life profilingSet location permission to ‘Never’ or ‘While Using App’ in device settings
Browsing and search historyBehavioral profiling, targeted manipulation, sensitive research exposureCannot be restricted if using in-app browser; use external browser for sensitive searches
Sensitive information (race, ethnicity, sexual orientation, religious beliefs)Targeted harassment, discrimination, physical safety risk if data is shared with law enforcement or third parties in certain jurisdictionsDo not share sensitive personal identity information; assume all profile information is permanent
ContactsSocial engineering of your contacts, relationship mapping for targeted attacksDeny contacts permission in device settings
Device signals (Bluetooth, Wi-Fi, cell towers)Physical location inference even without GPS accessCannot be restricted through app settings; requires device-level changes

Update Log

DateEvent
July 6, 2023Threads launches globally (excluding EU); reaches 1 million users within 1 hour; 100 million users within first week
July 2023Privacy advocates and regulators raise concerns about Threads’ data collection categories disclosed in App Store privacy disclosure
December 2023Threads launches in the European Union after Meta makes commitments to EU regulators on data handling compliance with DMA and GDPR
July 2023 (original post)Original blog post published analyzing Threads’ privacy concerns and security implications
September 2026 (this update)Content updated with privacy risk assessment table, data category impact breakdown, update log, EU launch context, and FAQ section

Conclusion

Threads stands out as a dynamic text-based communication and content-sharing platform, but it also brings heightened concerns about data privacy and security. While users can modify settings and restrict some data collection at the device level, the extensive data collection capabilities described in Meta’s privacy policy raise significant concerns, particularly given the breadth of sensitive data categories that Threads can access. To ensure a secure experience on Threads, users must adopt proactive security measures, enable two-factor authentication, restrict device permissions, use strong unique passwords, and exercise caution about what personal data they share on the platform. The scale of data collection that Threads enables, particularly when cross-referenced with data from other Meta platforms, means that users who engage with Threads without these protections are providing significantly more personal information than they may realize. Encryption Consulting provides data protection services including CodeSign Secure, CertSecure Manager, PKI-as-a-Service, and HSM-as-a-Service. Please contact us at [email protected] for any queries about security solutions.

Frequently Asked Questions

What personal data does Threads collect according to its App Store privacy disclosure?

Threads’ App Store privacy disclosure indicates it can collect: health and fitness information, financial information, contact information, browsing and search history, location data including GPS, purchases, user content, usage data, device information, identifiers, sensitive information (which can include race, ethnicity, and sexual orientation), and other data under Meta’s broader privacy policy. Meta can cross-reference this data with information collected on Facebook and Instagram to build comprehensive user profiles.

Why is the volume of data Threads collects a cybersecurity concern?

Concentrated data aggregation creates a high-value breach target: the more personal data a platform holds across health, financial, location, and behavioral dimensions, the more damaging a breach becomes. The combination of these data categories enables profiling that can facilitate targeted attacks, social engineering, and physical surveillance more effectively than any individual data point alone. Data shared with third parties distributes this risk further beyond the original collection context.

Why was Threads not launched in the European Union at launch?

Threads was not initially available in the EU due to concerns about how Meta handles user data across its platforms and compliance with the Digital Markets Act (DMA) and GDPR, which impose restrictions on data sharing between services operated by large digital platforms. Meta addressed these regulatory concerns, and Threads launched in the EU in December 2023.

What are the most important steps a Threads user can take to protect their privacy?

The most important steps are: enable two-factor authentication using an authenticator app; restrict app permissions in device settings (especially location, camera, and contacts); use a strong unique password not reused from other services; avoid sharing sensitive personal, financial, or health information on the platform; regularly review privacy settings and follower lists; and keep the app and device operating system updated to benefit from security patches.

Can the sensitive data Threads collects be used for purposes beyond advertising?

Yes. Meta’s privacy policy states that data may be shared with third parties including marketers and law enforcement agencies. Sensitive data categories Threads may collect, including race, ethnicity, sexual orientation, biometric data, pregnancy status, political beliefs, and religious beliefs, carry risks beyond advertising exposure: unauthorized access through a breach, sharing with law enforcement in jurisdictions with discriminatory enforcement, or use in targeted harassment can create safety risks for users whose sensitive personal information is exposed.