A database containing the leaked phone numbers (and other personal information) of some 533 million Facebook users has just been spotted online. The database was posted to a low-level hacking forum for free.
Yikes!
Here’s what Business Insider said:
The exposed data includes personal information of over 533 million Facebook users from 106 countries, including over 32 million records on users in the US, 11 million on users in the UK, and 6 million on users in India. It includes their phone numbers, Facebook IDs, full names, locations, birthdates, bios, and — in some cases — email addresses.
Insider reviewed a sample of the leaked data and verified several records by matching known Facebook users’ phone numbers with the IDs listed in the data set. We also verified records by testing email addresses from the data set in Facebook’s password reset feature, which can be used to partially reveal a user’s phone number.
A Facebook spokesperson told Insider that the data was scraped due to a vulnerability that the company patched in 2019.
While a couple of years old, the leaked data could provide valuable information to cybercriminals who use people’s personal information to impersonate them or scam them into handing over login credentials, according to Alon Gal, CTO of cybercrime intelligence firm Hudson Rock, who first discovered the entire trough of leaked data online on Saturday.
This is extremely bad and whether this hack happened 2 years ago or 2 minutes ago. Here’s why:
Here’s how Facebook should be punished for this latest screw up. Facebook has a market cap of over $800 billion. So I suggest a fine of $80 per account. For the roughly half billion accounts exposed, that would come to $40 billion, or about 5% of their market capitalization. That would really get their attention and you would bet your last dollar that Facebook would never, ever be this negligent again.
Let’s see if that happens. But I don’t think it will.
UPDATE: David Masson, Director of Enterprise Security for Darktrace had this to say:
The events of this weekend surrounding Facebook highlights the urgent necessity for an approach to security that stops threats, even once they have penetrated the perimeter. Though the Facebook data exposure is a reiteration of a previous breach, it demonstrates the severity of these kinds of attacks. The ramifications of personal data theft and abuse continue to be felt not just by Facebook, but also by the victims of the breach years after the initial incident. Ultimately, businesses need an approach to security that gives them complete visibility into their digital enterprises, that helps them understand exactly where users and data are at all times, and gives them the ability to autonomously respond to threatening activity – before the damage is done.
Guess What? Facebook Has A ‘Dangerous Vulnerability’ That Exposes Millions Of Email Addresses….. A Huge Reason To #DeleteFacebook
Posted in Commentary with tags Facebook on April 22, 2021 by itnerdA security researcher has made public a Facebook vulnerability exposing millions of user email addresses after Facebook allegedly dismissed the exploit when he reported it to them. Ars Technica has viewed a video created by the researcher demonstrates the exploit:
A video circulating on Tuesday showed a researcher demonstrating a tool named Facebook Email Search v1.0, which he said could link Facebook accounts to as many as 5 million email addresses per day. The researcher—who said he went public after Facebook said it didn’t think the weakness he found was “important” enough to be fixed—fed the tool a list of 65,000 email addresses and watched what happened next.
“As you can see from the output log here, I’m getting a significant amount of results from them,” the researcher said as the video showed the tool crunching the address list. “I’ve spent maybe $10 to buy 200-odd Facebook accounts. And within three minutes, I have managed to do this for 6,000 [email] accounts.”
Facebook said this in response:
In a statement, Facebook said: “It appears that we erroneously closed out this bug bounty report before routing to the appropriate team. We appreciate the researcher sharing the information and are taking initial actions to mitigate this issue while we follow up to better understand their findings.”
A Facebook representative didn’t respond to a question asking if the company told the researcher it didn’t consider the vulnerability important enough to warrant a fix. The representative said Facebook engineers believe they have mitigated the leak by disabling the technique shown in the video.
But here’s what the researcher said about how Facebook responded to his initial report:
The researcher, whom Ars agreed not to identify, said that Facebook Email Search exploited a front-end vulnerability that he reported to Facebook recently but that “they [Facebook] do not consider to be important enough to be patched.” Earlier this year, Facebook had a similar vulnerability that was ultimately fixed.
“This is essentially the exact same vulnerability,” the researcher says. “And for some reason, despite me demonstrating this to Facebook and making them aware of it, they have told me directly that they will not be taking action against it.”
Total #Fail for Facebook. But the #Fail gets worse:
An email Facebook inadvertently sent to a reporter at the Dutch publication DataNews instructed public relations people to “frame this as a broad industry issue and normalize the fact that this activity happens regularly.” Facebook has also made the distinction between scraping and hacks or breaches.
This is now an #EpicFail because it is clear that Facebook doesn’t care about its users and protecting them. If this combined with Facebook’s other #EpicFails doesn’t make you want to #DeleteFacebook, nothing will.
Leave a comment »