How a Twitter employee sold user data to Saudi Arabia for a watch and cash
A Twitter manager whose job was working with journalists and celebrities in the Middle East looked up private details behind accounts critical of the Saudi royal family, after leaving a meeting in London with a $42,000 watch.[1][7] This case file covers how an insider with the wrong kind of access became a source for a foreign government, how the case unfolded in court, and the one control that would have made his job useless to them.
What happened
Ahmad Abouammo was Twitter's media partnerships manager for the Middle East and North Africa, a role overseeing the company's relationships with journalists and celebrities in the region.[2][7] Prosecutors said a Saudi official first contacted him in June 2014.[4] In December 2014 the two met in London, and Abouammo came away with a Hublot watch worth about $42,000.[1]
He then looked up private information behind accounts critical of the Saudi government, including at least one influential account that criticized the royal family.[1][4] Court testimony showed he opened that account's records 7 times between December 2014 and February 2015.[4] The kind of data at stake included email addresses, phone numbers, IP addresses and dates of birth, details that can help identify and locate an anonymous user.[3]
In February 2015 he flew to Lebanon, where a bank account was opened in his father's name and $100,000 arrived from the official. He then moved the money into the U.S. in smaller wires.[2] He left Twitter in 2015, and another $100,000 followed afterward.[1][4] Prosecutors said a second employee, a Twitter engineer, was also passing user data to Saudi officials. When company managers confronted that engineer, he left the U.S. the next day and resigned by email on the way.[3]
How it worked
No hacking was involved. Abouammo used an internal Twitter tool that let staff view the account details behind a username. He simply typed in the accounts the official cared about and passed on what he saw.[4] Prosecutors described it as using employee credentials to reach nonpublic information without authorization, in breach of company policy.[3]
The weak spot was that the tool let him see it at all. Twitter's head of safety testified at trial that someone on the partnerships team had essentially one reason to use it: checking whether an inactive username could be handed to a new owner.[4] Looking up the phone number or login location of a critic was never part of the job, yet nothing stopped a partnerships manager from doing it, and nothing flagged it in time to protect the people whose data was exposed.
How it was caught
The trail went cold for years. FBI agents interviewed Abouammo at his Seattle home in October 2018. He gave them a false explanation for the money and backed it up with a fake consulting invoice he sent to the agents.[5][6] He was arrested on November 5, 2019, and charges were also filed against the engineer and a Saudi intermediary.[1][3]
What it cost
On August 9, 2022, a jury convicted Abouammo of acting as an agent of Saudi Arabia without notifying the U.S. government, conspiracy, wire and honest services fraud, international money laundering and falsifying records. He was acquitted on 5 other fraud counts.[1] On December 15, 2022, a judge sentenced him to 42 months in prison and ordered $242,000 forfeited.[1] Prosecutors had asked for about 7 years.[7]
The case kept moving on appeal. In December 2024 the Ninth Circuit upheld the fraud and foreign agent convictions but sent the case back for resentencing over how loss had been calculated.[8] On June 11, 2026, the Supreme Court unanimously threw out only the falsified-records conviction, ruling it should have been tried in Seattle, where he made the fake invoice.[6] The other convictions were not affected by that ruling.[6]
The missing control
The missing control: role-based access to user data. A partnerships manager could pull private account details that his role almost never needed.
If access had been tied to the job, the tool would have shown him a username's status and nothing more. Asking for a phone number or IP address would have required a documented reason and approval from someone in a trust and safety role. Even a simple alert on staff looking up the same sensitive account 7 times in 2 months would have raised the question months or years earlier.[4] The watch and the wire transfers bought an insider. Role-based access would have left that insider with little worth selling.
What to do in your business
- Map access to jobs, not people. For each role, write down which customer records it truly needs. Sales may need contact details; it rarely needs payment or ID data.
- Turn off the extras in your tools. Most CRMs, booking systems and payroll apps let you limit fields and screens by user role. Use them instead of giving everyone full admin.
- Log and review lookups of sensitive records. Keep a record of who viewed which customer file, and check it monthly for staff pulling records outside their normal work.
- Add a reason prompt for sensitive data. Where possible, require staff to enter a ticket or reason before opening full customer details. It deters casual snooping and leaves a trail.
- Set a clear gifts and outside-payment rule. Require staff to report gifts over a small amount and any outside consulting work. Unexplained luxury gifts are a warning sign worth asking about.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Hot Lotto was rigged: the security director who wrote the numbers
- The Ubiquiti hack was an inside job: how a senior developer extorted his employer
- How the Coinbase data breach happened: bribed support agents and a $20 million demand
- How one trader brought down Barings Bank: account 88888
- The Tesla insider bribe plot: the $1 million offer an employee reported
- How a security training company hired a North Korean fake IT worker
- Every insider risk control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- U.S. Attorney's Office, N.D. Cal.: Former Twitter employee sentenced to 42 months in federal prison for acting as a foreign agent
- U.S. Department of Justice: Former Twitter employee found guilty of acting as an agent of a foreign government and unlawfully sharing Twitter user information
- U.S. Department of Justice: Two former Twitter employees and a Saudi national charged as acting as illegal agents of Saudi Arabia
- Courthouse News Service: Trial of ex-Twitter employee accused of spying for Saudi Arabia opens
- CBS News: Former Twitter worker convicted of spying for Saudi Arabia
- Al-Monitor (Reuters): US Supreme Court overturns ex-Twitter employee's obstruction conviction in Saudi spy case
- Global News: Ex-Twitter employee sentenced for spying for Saudi Arabia
- Bloomberg Law: Ex-Twitter staffer gets sentence thrown out in Saudi spying case