frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

My first experience with an "AI"-ed call centre?

3•chrisjj•44m ago•0 comments

Perfect agreement is a warning sign you're talking to yourself

2•eldude•1h ago•0 comments

Ask HN: Are you a SWE that lost job purely due to AI? Share your story

2•matijash•12m ago•0 comments

Reddit Ads support is leaking PII and actively crossing user sessions

7•arashvakil•2h ago•1 comments

Thank HN: You helped save 33k lives

1135•chaseadam17•3d ago•113 comments

Ask HN: Is it worth learning Vim in 2026?

24•zekejohn•14h ago•17 comments

Google Cloud APIs (gcloud CLI) seems to be down or broken

3•thej•11h ago•0 comments

Ask HN: Anyone else tired of working in tech?

30•boredemployee•1d ago•35 comments

Googling on Brazil about "Gemini said" shows unrevised content from Gemini

3•yrds96•1d ago•1 comments

Ask HN: Are hackathons still worth doing?

8•kwar13•1d ago•6 comments

Ask HN: Can a license make large corporations give back?

2•arboles•1d ago•3 comments

Ask HN: (Your) Request for Startups?

9•dontoni•1d ago•7 comments

Ask HN: How do you overcome imposter syndrome?

11•fdneng•2d ago•16 comments

Ask HN: How do you motivate your humans to stop AI-washing their emails?

27•causal•3d ago•35 comments

Ask HN: In Cursor/agents, do plugins hide MCP tools from the main agent?

4•azebazenestor•1d ago•3 comments

Ask HN: Why are there no talks about Seedance 2.0 on Hacker News?

8•ElectroNomad•2d ago•7 comments

Watching an elderly relative trying to use the modern web

48•ColinWright•3d ago•19 comments

Tell HN: Attackers using Google parental controls to prevent account recovery

19•TazeTSchnitzel•2d ago•4 comments

Top non-ad google result for "polymarket" in Australia is a crypto scam

17•rtrgrd•4d ago•3 comments

Ask HN: Claude web blocked its assets visit via csp?

6•xgstation•2d ago•2 comments

Ask HN: Companies that advertise being a "best place to work", is it a red flag?

12•jrs235•4d ago•16 comments

SEL Deploy – Cryptographically chained deployment timeline

2•chokriabouzid•2d ago•1 comments

Picknar – Lightweight YouTube Thumbnail Extractor (No Login, No API Key)

3•Picknar•3d ago•1 comments

Grand Time: Time-Based Models in Decentralized Trust

3•AGsist•3d ago•0 comments

Ask HN: How do you debug multi-step AI workflows when the output is wrong?

4•terryjiang2020•2d ago•7 comments

You've reached the end!

Open in hackernews

Reddit Ads support is leaking PII and actively crossing user sessions

7•arashvakil•2h ago
I have been dealing with a Reddit Ads account issue over the last week, and it has quickly escalated into a severe privacy and security red flag. It appears their customer support tools (or the agents themselves) are actively bleeding PII and crossing user sessions entirely.

Over the last week, I have experienced three separate incidents in their live chat:

Incident 1: Account Cross-Contamination (Feb 14) While chatting with an agent (Sonam B), they managed to associate my personal email to a completely unrelated, bizarrely named ad account ("No Panties Games Ad Account"). When I pointed out they were pasting data related to someone else's account alongside my email, they tried to brush it off as an "error" and told me to "kindly ignore."

Incident 2: Direct PII Leak (Feb 20) Today, while following up on the issue with a different agent (Naheeda M), they inexplicably dropped the email address (info@REDACTED.com) and the full legal business entity name of an entirely different advertiser into our chat.

Incident 3: Total Session Confusion and Misattribution (Feb 20) Just minutes later in that same chat, things got much worse. While I was clearly logged into my own account, the agent told me: "The ad account you're currently signed into is u/TeorREDACTED, and ads are getting published with this username. Is that correct?"

This is no longer just a clipboard issue. This strongly suggests a severe backend mapping failure in their support dashboard (Zendesk/Salesforce or an internal admin tool) that is completely misattributing active sessions, user accounts, and ad publishing data.

If their support agents are seeing me as logged into someone else's account and claiming ads are publishing under that username, it raises massive questions: 1. Are agents making changes to other people's ad campaigns thinking it's my account? 2. Is ad spend being billed to the wrong accounts? 3. Who is currently seeing my billing details, legal name, and campaigns?

Given how broken their Tier 1 tools appear to be right now, I wanted to raise the flag here immediately. Has anyone else running Reddit Ads noticed their support agents leaking data or confusing accounts recently?

Comments

toomuchtodo•2h ago
https://www.cisa.gov/reporting-cyber-incident at the federal level, if you have a state regulator where PII is in scope, report to them too. Document everything for your complaint as evidence. A GitHub Gist collecting your documentation, archived by the Wayback Machine is an effectively public timestamp mechanism if relevant.