Data of 235 million Instagram, YouTube, TikTok users exposed: Report

According to security researchers from pro-consumer website Comparitech, an unsecured database was behind this data breach

Instagram
One in five records contained either a telephone number or email address of the users.
IANS San Francisco
2 min read Last Updated : Aug 21 2020 | 10:47 AM IST

At least 235 million users of Facebook-owned Instagram, China-based TikTok and Google-owned YouTube have been hit by a massive data leak and their personal profiles were up for grabs on the Dark Web.

According to security researchers from pro-consumer website Comparitech, an unsecured database was behind this data breach.

"The data was spread across several datasets and the most significant being two coming in at just under 100 million each and containing profile records apparently scraped from Instagram," reports Forbes, quoting the security researchers.

The third-largest was a dataset of some 42 million TikTok users, followed by nearly 4 million YouTube user profiles.

One in five records contained either a telephone number or email address of the users, along with profile name, full real name, profile photo, account description and number of followers and likes, etc.

"The information would probably be most valuable to spammers and cybercriminals running phishing campaigns," said Paul Bischoff, Editor at Comparitech.

"Even though the data is publicly accessible, the fact that it was leaked in aggregate as a well-structured database makes it much more valuable than each profile would be in isolation," Bischoff said in the report on Thursday.

According to the researchers, the leaked data points to a company called Deep Social banned by both Facebook and Instagram in 2018 after scraping user profile data.

"Scraping people's information from Instagram is a clear violation of our policies. We revoked Deep Social's access to our platform in June 2018 and sent a legal notice prohibiting any further data collection," a Facebook spokesperson was quoted as saying.

According to Comparitech, data marketing company Social Data later shut the unsecured database after it was reported to them.

"Social Data has denied any connection between itself and Deep Social," according to the Comparitech report.

Earlier this month, a hacker group known as ShinyHunters flooded a hacker forum with 386 million user records stolen from 18 companies.

According to BleepingComputer, ShinyHunters began uploading the databases to a forum where anyone can download them free of charge. Of the databases released since July 21, nine of them were already disclosed in some manner in the past.

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :InstagramFacebookYouTubedata leakage

First Published: Aug 21 2020 | 10:36 AM IST

Next Story