Twilio is erroneously over-billing and suspending accounts
status.twilio.com
status.twilio.com
If this has happened to your account, please send an email to help@twilio.com where we have our support team working on making this right for everyone affected. We are spinning up additional resources to make sure every customer issue gets resolved as quickly as we can.
Link for this article goes to our status board which serves as the authoritative source of information on this incident. We will be delivering updates every half hour or as new information becomes available.
We are very sorry. This is far short of our commitment to you. We'll have more on the incident and what we will do to make this right later today.
We've been with Twilio for years and have received excellent service. Billing issues are always serious, but its nothing compared to a call routing issue, and when it comes to call routing Twilio has been flawless. I'd much rather call my bank and discuss an overdraft fee then call a client and explain why their calls were not routed properly.
In the years we've been with Twilio, we have not experienced any significant downtime. Compare that to one of their main competitors that experienced eight consecutive hours of downtime during business hours earlier this year, and I'm confident we're in good hands.
We came up way short for you this morning - committed to making it right.
When you get some time (I'm sure you have none right now), read some of the Dreamhost discussion below. You folks appear to be doing an excellent job responding to this.
This is also great as a "how not to tell customers that you just double billed them." At least Twilio is getting this right.
http://dreamhost.com/dreamscape/2008/01/15/um-whoops/
Step 1: Don't complain to the customer how inconvenient your massive mistake was for you.
I can see why you'd still be annoyed about not getting your charges refunded though. What happened there? Frankly, if your bank didn't refund them when you told them what happened, they seem pretty scummy. I hope you dumped them as soon as you could!
As for what's wrong with the post, a ton. This was e-mailed to every single customer. For many people, myself included, this was their first notice that something was wrong with their finances. And it was the author's fault. The line you quoted was at the end of a very long post. The apology should have been right in the first paragraph. Instead in the first two lines he's complaining about how bad this is for him.
Then he makes a bunch of jokes. Then he explains why it was just tiny mistake. Don't feel bad if I missed the problem? I'm not the one being trusted with millions of dollars of your customer's money... [Edit: to me that bit reads as "See? You missed it too! Now why should I feel bad?"]
After all this, finally, he apologizes.
For me, this guy's mistake meant that I now had to worry about how I was going to pay bills/rent, and how I was going to eat. My situation was probably quite unique, but that didn't make it any less impactful for me.
To me the whole thing reads as "I just accidentally removed a few million dollars from my customers banks/credit lines - so now I'm gonna have a laugh with them!"
I can say with great confidence that I'm not immune to the mistakes that caused this to happen. But what I can say is that were I in his shoes, I'd lead with an apology, be very succinct about what happened, and finally list details as to how I'm going to make it better.
Edit: To his credit, if you read the next post he did a much, much better job there.
Edit 2: And also for what it's worth - I still use Dreamhost. Aside from this SNAFU they've ran an excellent service, and (again, except in this case) their customer service has been excellent in responding to any issues I've had. However now I always pay with credit rather than debit, and I don't store my card info.
But then, it's easy enough for me to view it in a generous light, when it had no personal effect on me. I would no doubt have felt very different had it been my account that was wiped out!
Oh, and yeah banks suck, especially when you're poor. Been there...
Maybe he could have worded it differently and shown less irreverence, but that may be a byproduct of the stress as well. It's a pretty shocking thing too and they're human after all.
My current web host uses them as a registrar for some years and they've been pretty happy with DH services.
On the banks... "Overdraft protection" is probably the single most disingenuous thing the banks have done to low-income individuals. It's such a "squeeze 'em when they're down" tactic. I had all kinds of financial problems in college, mostly my own doing, but they were sooo complicated by this... service. Suddenly because of one mistake, 10 small transactions turns into an additional $320 expense. Three days later you get 10 little envelopes in the mail. And then the dread. "Shit, I did it again. Now what am I gonna do?"
To the best of my knowledge, SunTrust wouldn't let you opt out prior to the CARD act. Or, if they did, none of their customer service reps or bank managers notified me of the possibility.
Thankfully I manage my finances better now. And thankfully the CARD act makes overdraft protection opt-in (although for a lot of banks this is just another clause in the phonebook-sized account agreement you sign), and there are now a few checking accounts (ING Direct, Ally bank) that treat payment of transactions that cause overdraft like what it is - a line of credit.
It's really, really handy and they don't advertise it at all. I found out about it when I accidentally ran up a dozen overdraft fees and talked to an account manager about how to keep it from happening again. I'd recommend that everyone see if their bank offers something similar.
With a debit card, an erroneous charge means the other guy has the money, and you have no power.
With a credit card, you still have your money until you pay your bill, so up to that point, you still have the power.
http://dreamhost.com/dreamscape/2008/01/15/um-whoops/
At the very least, it would be wise for any company to implement billing features that will under bill rather than overbill. Under billing at least gives you the option of notifying users later (or you just eat it). Overbilling can sour a professional relationship to the point of ending it.
Having built several automation systems that bill millions of dollars, I can say that it's quite challenging to build things that have no visible output, run by themselves and often sit there for years without being touched, while everything changes around them!
It's not sexy work, but when it goes wrong the shit really can hit the fan!
if prorated_amount > (cost_per_month * 2)
raise "critical! we were about to prorate-charge someone #{prorated_amount}"
end
It's never been triggered, but this is probably the only place in our system where we're actually responsible for an exact amount that ends up on an invoice, so having a reasonable upper limit seems like a no-brainer.This code -- while good for catching bad single calculations -- wouldn't catch that.
We can't prevent every mistake but we can make sure the same one doesn't happen again.
Looks like their auto-recharge balance test keeps returning 0 or less than 0, it charges your card, and loop.
EDIT: Looks like they're doing something - the UI at least now displays $500, rather than $10k before. The only real confidence I'll get is when I can see todays account transactions from the bank.
We just unsuspended the accounts affected by this incident and are currently working on the balances.
If you haven't already, please send an email to help@twilio.com indicating you are affected by the incident so we can communicate directly as we correct these erroneous charges.
There will be account balance changes in the Dashboard UI as we address the erroneous billing.
If you haven't already, please send us an email to help@twilio.com so we can keep you directly updated on our recovery work.
If you haven't already, please send an email to help@twilio.com so we can let you know directly the resolution for this billing error.
"Twilio is over-billing ..." = Twilio is charging more than they should.
"Twillio is over billing ..." = Twilio has given up on billing. It's so over.
Just my personal bugbear - but sometimes it's worth getting this sort of thing correct. Apologies if this is just a US/UK difference, also (I'm in the UK).
https://www.google.com/search?q="overbilling" vs. https://www.google.com/search?q="over-billing"
I was one of the customers affected. Luckily for me, my credit card automatically blocked the transaction after the 10th time I was auto-recharged, meaning I had a cap on how much I paid. I can totally understand the frustration of people discovering that they suddenly have 100's or even 1000's of dollars worth of charges to their credit card.
On the other hand, by the time I noticed that something strange was going on, Twilio's status page already said they were looking into it. I contacted their support right away, and they answered within 20 minutes, during what must be a customer support crisis.
And now RobSpectre is on HN giving very helpful answers.
So, no, it's not their finest work (as RobSpectre has said), but at least they're dealing with it quickly, and hopefully professionally as well. Let's let this play out before we jump up and down on a great company that we all love.
Lot of work to do to make up for this shortcoming.
Debit/bank users are definitely the most susceptible.
So I would wait and see, how this is handled. I see updates about every half hour, so I suspect, that they will handle the rest as transparent as well...
Disclaimer: Not a customer.
We'll have more on what caused this incident and what we're going to do to make it right later today.
OP link directs to the board with our up-to-the-minute status on resolving this incident.
From a developer point of view, we all have bugs. I remember the first time one of my bugs impacted customers and it was awful. If there's any community that should be understanding that things like this happen in the tech world, it should be us.
We fell short of your expectations today. More later today on how we'll get this right.
Very much appreciate your support through a difficult night and morning. More to come.
Even if Twilio's somehow able to ignore the pain of telco engine rating and least-cost-routing, there are still so many places you can make an error and cause something like this.
Kudos to Rob and team for owning the issue and I hope the Twilio folks get this sorted out (I'm confident they will). It's worth mentioning that I've never seen another billing issue of this size from Twilio so one in 3-4 years isn't too awful. Compared to AT&T it's probably generous! (Facetious but with a grain of truth).
Good luck guys and keep rocking. Here's hoping everything works out.
I don't believe any of these technologies have any failsafes built-in related to credit card processing (or overcharging), and so anyone who uses these systems has to perform their own sanity checks.
It's extremely rare for billing to screw up in Telecom, because, essentially, that is the crux of all Telco business. Twilio is probably using a homegrown or Non-telecom billing system, but I don't have any insight into their operations. I would hazard a guess that it's homebrewed though as I can't imagine a processing company introducing an error like this (stranger things have happened).
So yeah, I think this will be a one time incident, and frankly, their response was fantastic.
Full text also here:
At 3:28am PDT/11:28am GMT, our monitoring systems reported an anomaly in our billing systems, which resulted in erroneous credit card charges and in some cases account suspensions. This incident affected 1.1% of customer accounts. The on call team immediately began an incident response, using the Twilio status dashboard at status.twilio.com to update customers at regular intervals. By 6:24am PDT/2:24pm GMT all suspended accounts had had service restored. The same problem briefly re-occurred at approximately 12:30pm PDT/8:30pm GMT, affecting 0.3% of customer accounts, which were immediately remedied.
At this time, the Twilio billing system is offline and account-balances are not being updated in real-time until we fully resolve the issue. We are actively processing credit card refunds, and you will see a transaction void or refund on your credit card statement shortly (most banks process these within 24-48 hours). While the billing issue is being resolved, all voice and messaging services continue to operate normally.
In addition to refunding erroneous credit card transactions, Twilio will also be crediting affected accounts an additional 10% of their last 30 days’ spend. We recognize that it’s not about the money, but our responsiveness to the situation that matters to you. If your account was affected, please consider this credit an acknowledgement of the inconvenience we’ve caused you. If affected customers incurred overdraft or over-limit fees due to this incident, we will also make them whole. We are in the process of contacting all affected customers via email. Additionally, we will be releasing a full postmortem on the incident once all events and root causes are known, as well as detailing the corrective steps we’ll be taking.
Our focus is on providing you the best quality service and experience, and we recognize that today’s disruption came up short of what you expect from Twilio. Please accept our apologies and know it is our mission to always be earning your trust and business.
As many have you have pointed out on Twitter, this is not a fun day for our team, and especially our engineers. We appreciate your support and your patience.
Sincerely, Jeff Lawson CEO & Co-founder
Cancelling a card (or letting it expire) prevents new authorisations, it does not cancel previous authorisations.
As I indicated above, please shoot us a note to help@twilio.com so we can make this right for you.
As I indicated above Daniel, if you haven't shot a note to help@twilio.com indicating you're affected by the incident, please do so we can communicate directly when this $480 mistake is corrected.
More to come.
This will also affect the Usage API for some users. If you would like an immediate update when these are restored, use the OP link (http://status.twilio.com/services/account-portal) or send an email to help@twilio.com.
We're moving as expeditiously as safety allows.
Very sorry again.
We will make this right.
Can you have your ops team reach out via help@twilio.com and we'll get them connected with a resource to keep them informed?
i've run some ecommerce sites and this is basic stuff - new payment modules, time to test card processing works properly.
Best of luck
So stop making excuses. An organization of this scale should be taking serious precautions (against code errors, bad hardware, malicious attacks, network problems, compiler bugs, cosmic ray induced bit errors, etc.) when building a credit card processor.
If something truly extraordinary comes out to justify this problem, I may be sympathetic. But Occams razor suggests this was avoidable (through good process, not "I should have seen that off by one error").
At least Twilio has some reasonable disclosure of these issues on their dashboard to inform people of what is going on. I'm sure they will rectify the issue as soon as they have everything back up and running.
Imagine a world where Saas vendors would be liable for economic loss their software bugs generated. You'd have to fill in a huge questionnaire to sign up and everybody would be paying a tailored, very high price to cover all the risks. Every software vendor would be in the insurance business.
We only get away with things like outsourcing, low quality work full of bugs, side jumpers into the industry, weekend developers, because no one is held accountable for software bugs and their consequences.
The only place people seem to care is when people life's are at risk, and even then we know how Therac-25 went out.
In this case, Twilio is obviously calling out to a billing provider of some sort. I've run into situations myself where the billing provider returns a status message equivalent to "failure" when it actually was successful. In that case, many billing systems will try again thereby double-billing or worse.