Personal data belonging to about 533 million Facebook users from 106 countries was published for free on a hacking forum. Facebook said the data had been scraped in 2019 by abusing a feature that has since been fixed.
What happened
- The data included phone numbers, Facebook IDs, names, locations, and in some cases email addresses and birth dates.
- The largest affected countries included Egypt, Italy, and the US, with millions of UK users also included.
- Attackers had exploited Facebook’s contact importer feature to match phone numbers to profiles; Facebook said it fixed the issue in 2019.
- In November 2022 Ireland’s Data Protection Commission fined Meta €265 million over the scraping.
Why it mattered
The leak put phone numbers of a large share of Facebook’s users into criminal hands, fuelling smishing and scam calls, and showed that scraping can amount to a serious data protection failure. It also raised questions about whether old data from a fixed flaw should be treated as a new incident requiring notification.
Lessons for organisations
Rate-limit and monitor features that let users look up other accounts, test APIs for enumeration risks, and warn customers when their data is exposed.
Source: The Record
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.