Journalists Found Biden’s Venmo Account in 10 Minutes. That Should Make You Worry.

The app’s friends lists are public, posing a national security risk for top officials.

Evan Vucci/AP

Fight disinformation: Sign up for the free Mother Jones Daily newsletter and follow the news that matters.

After the New York Times published a story on Friday that mentioned President Biden sending his grandkids money over Venmo, a group of journalists at BuzzFeed News decided to track down his account and pulled it off in less than 10 minutes, thanks to a privacy hole in the app that has been known for years.

The ease with which reporters were able to track down Biden’s account, as well as his connections on the app, presents a national security threat, notes BuzzFeed, as well as privacy concerns for anyone who uses Venmo to exchange funds with friends. 

The app feature that enabled this rapid sleuthing is Venmo’s public friends lists. Users can opt to keep their transactions private, but there is no way to keep their friends in the app from public view. By looking up Biden’s family members, BuzzFeed reporters were able to find the president himself and then map out “a social web that encompasses not only the first family, but a wide network of people around them, including the president’s children, grandchildren, senior White House officials, and all of their contacts on Venmo.”

The national security concern here is twofold. The public nature of Venmo contacts for high-powered officials can expose those officials’ social circles and habits, posing a risk to the safety of all involved contacts. It can also expose these contacts to harassment and spamming by users. BuzzFeed found that at least one stranger had already tried to spam Biden’s extended family with requests in the app. Similarly, when people tracked down the Venmo accounts of Trump adviser Kellyanne Conway and then-White House Press Secretary Sean Spicer in 2017, both were flooded with bogus payments and payment requests in the Venmo app. 

After BuzzFeed contacted the White House for comment, all of these friends attached to Biden’s account disappeared. Venmo told BuzzFeed, “The safety and privacy of all Venmo users and their information is always a top priority, and we take this responsibility very seriously.”

This episode highlights what has been a years-long campaign by media and internet privacy experts asking Paypal, which owns Venmo, to enable users to make their contacts in the app private. They’ve also pushed Venmo to make transactions in the app private by default; currently, those transactions are public unless users change their settings.  

These settings have been shown time and again to pose a privacy risk. In 2018, one researcher was able to use publicly accessible information on Venmo to uncover the intimate details of users’ lives, from the mundaneā€”like grocery trips or vet appointmentsā€”to the salacious, like flirting, breakups, and drug deals. The next year, another researcher did something similar, scraping transaction data for 115,000 users per day. Just last month, the Daily Beast was able to uncover payments by Rep. Matt Gaetz (R-Fla.) to an accused sex trafficker, thanks to the public transactions in his Venmo account. Similarly, federal prosecutors recently used public Venmo information to track down and charge an alleged murderer. 

The public friends lists, too, have exposed a number of secrets. One fan was able to use them to figure out who won a 2020 season of the Bachelor. BuzzFeed used public contacts on Venmo to track down reporters who were friends with Trump administration officials and congressmen who were roommates. Recently, several state bar associations have started issuing guidance for attorneys about using Venmo to accept payment from clients, assessing how the public nature of the app might mix with the confidentiality requirements to which lawyers are beholden. 

Former Venmo employees told BuzzFeed that the public friends lists and transaction logs were integral to Venmo’s early design, which sought to replicate the success of social networks in order to attract more users and cultivate trust among them.  

This episode exposing the accounts of the president, his wife, and their family and closest associates is now the latest to highlight the privacy pitfalls of this social, public-by-default design. 

WE'LL BE BLUNT

It is astonishingly hard keeping a newsroom afloat these days, and we need to raise $253,000 in online donations quickly, by October 7.

The short of it: Last year, we had to cut $1 million from our budget so we could have any chance of breaking even by the time our fiscal year ended in June. And despite a huge rally from so many of you leading up to the deadline, we still came up a bit short on the whole. We canā€™t let that happen again. We have no wiggle room to begin with, and now we have a hole to dig out of.

Readers also told us to just give it to you straight when we need to ask for your support, and seeing how matter-of-factly explaining our inner workings, our challenges and finances, can bring more of you in has been a real silver lining. So our online membership lead, Brian, lays it all out for you in his personal, insider account (that literally puts his skin in the game!) of how urgent things are right now.

The upshot: Being able to rally $253,000 in donations over these next few weeks is vitally important simply because it is the number that keeps us right on track, helping make sure we don't end up with a bigger gap than can be filled again, helping us avoid any significant (and knowable) cash-flow crunches for now. We used to be more nonchalant about coming up short this time of year, thinking we can make it by the time June rolls around. Not anymore.

Because the in-depth journalism on underreported beats and unique perspectives on the daily news you turn to Mother Jones for is only possible because readers fund us. Corporations and powerful people with deep pockets will never sustain the type of journalism we exist to do. The only investors who wonā€™t let independent, investigative journalism down are the people who actually care about its futureā€”you.

And we need readers to show up for us big timeā€”again.

Getting just 10 percent of the people who care enough about our work to be reading this blurb to part with a few bucks would be utterly transformative for us, and that's very much what we need to keep charging hard in this financially uncertain, high-stakes year.

If you can right now, please support the journalism you get from Mother Jones with a donation at whatever amount works for you. And please do it now, before you move on to whatever you're about to do next and think maybe you'll get to it later, because every gift matters and we really need to see a strong response if we're going to raise the $253,000 we need in less than three weeks.

payment methods

WE'LL BE BLUNT

It is astonishingly hard keeping a newsroom afloat these days, and we need to raise $253,000 in online donations quickly, by October 7.

The short of it: Last year, we had to cut $1 million from our budget so we could have any chance of breaking even by the time our fiscal year ended in June. And despite a huge rally from so many of you leading up to the deadline, we still came up a bit short on the whole. We canā€™t let that happen again. We have no wiggle room to begin with, and now we have a hole to dig out of.

Readers also told us to just give it to you straight when we need to ask for your support, and seeing how matter-of-factly explaining our inner workings, our challenges and finances, can bring more of you in has been a real silver lining. So our online membership lead, Brian, lays it all out for you in his personal, insider account (that literally puts his skin in the game!) of how urgent things are right now.

The upshot: Being able to rally $253,000 in donations over these next few weeks is vitally important simply because it is the number that keeps us right on track, helping make sure we don't end up with a bigger gap than can be filled again, helping us avoid any significant (and knowable) cash-flow crunches for now. We used to be more nonchalant about coming up short this time of year, thinking we can make it by the time June rolls around. Not anymore.

Because the in-depth journalism on underreported beats and unique perspectives on the daily news you turn to Mother Jones for is only possible because readers fund us. Corporations and powerful people with deep pockets will never sustain the type of journalism we exist to do. The only investors who wonā€™t let independent, investigative journalism down are the people who actually care about its futureā€”you.

And we need readers to show up for us big timeā€”again.

Getting just 10 percent of the people who care enough about our work to be reading this blurb to part with a few bucks would be utterly transformative for us, and that's very much what we need to keep charging hard in this financially uncertain, high-stakes year.

If you can right now, please support the journalism you get from Mother Jones with a donation at whatever amount works for you. And please do it now, before you move on to whatever you're about to do next and think maybe you'll get to it later, because every gift matters and we really need to see a strong response if we're going to raise the $253,000 we need in less than three weeks.

payment methods

We Recommend

Latest

Sign up for our free newsletter

Subscribe to the Mother Jones Daily to have our top stories delivered directly to your inbox.

Get our award-winning magazine

Save big on a full year of investigations, ideas, and insights.

Subscribe

Support our journalism

Help Mother Jones' reporters dig deep with a tax-deductible donation.

Donate