Facebook admits leaked data on 533 million users back online for free

The leak includes personal information such as phone numbers, full names and locations.

facebook
Kurt Wagner | Bloomberg
2 min read Last Updated : Apr 04 2021 | 5:31 AM IST
The personal data of more than half a billion Facebook Inc. users reemerged online for free on Saturday, a reminder of the company’s ability to collect mountains of information and its struggles to protect these sensitive assets.

The leak includes personal information on 533 million Facebook users, such as phone numbers, Facebook IDs, full names, locations, birth dates, bios and in some cases email addresses, Business Insider reported.

“This is old data that was previously reported on in 2019,” a Facebook spokesperson wrote in an email statement. “We found and fixed this issue in August 2019.”

At the time, the company addressed a flaw in its technology that allowed the information to leak out. However, once such data escapes from Facebook’s network, the company has limited power to stop it from spreading online.

Alon Gal, chief technology officer of cybercrime intelligence firm Hudson Rock, discovered the data again on Saturday.


Databases, especially if they are large or rare, aren’t often shared widely right away because “the people who hold it will attempt to monetize it for as long as they can,” Gal said in a message on Twitter. “The process sometimes takes years, sometimes days, but eventually all private databases leak if they were sold around.”

Data leaks threaten to undermine Facebook’s business model of gathering a large amount of personal information and using that to sell targeted ads.

The information is available for free on a hacking forum, making it widely accessible to anyone with rudimentary data skills, Business Insider said. The publication verified several records by matching known Facebook users’ phone numbers with the IDs listed, and confirmed other records by testing email addresses from the data set in Facebook’s password reset feature, which can be used to partially reveal a user’s phone number.

(Updates with comment from cyber intelligence firm that discovered data leak in sixth paragraph.)

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Topics :Facebookfacebook data leakdata protection

Next Story