Over 267 million Facebook usernames and phone numbers are leaked online

Facebook Privacy

According to a recent report, a database containing more than 267 million Facebook usernames and phone numbers have been exposed on the web without any password protection or any other authentication. By having the web URL anyone can access the database, as it does not require a password or any other authentication.

Security researcher Bob Diachenko partnered with Comparitech uncovered the Elasticsearch database, the database found to be open for nearly two weeks. The non-password-protected Elasticsearch cluster was located on December 14, but it was first indexed by search engines on December 4, 2019. The researcher notified the ISP that managed the IP address of the leaking server, and the database was taken down on December 19. However, this time we can say with certainty that malicious actors accessed it, as the data was posted on a darknet forum on December 12.

Security researcher Bob Diachenko discovered the unsecured database. The database is believed to be a “result of an illegal scraping operation or Facebook API abuse by criminals in Vietnam, according to the evidence”.

According to Comparitech, the database included a user’s Facebook ID, their phone number, full name, and a timestamp. The majority of the users affected were from the United States.

In total 267,140,436 Facebook users’ records were exposed. Most of the affected users were from the United States. The server included a landing page with a login dashboard and a welcome note.

Bob Diachenko
Facebook - User Details Leaked
Facebook – User Details Leaked

Facebook IDs are unique, public numbers associated with specific accounts, which can be used to discern an account’s username and other profile info. Though the database is no longer available online as of Thursday, it is possible that it was copied elsewhere prior to being taken down, Comparitech warned, noting that all the data appeared to be valid.

Facebook has not officially revealed the number of affected users. However, it is in the process of investigating the incident. A Facebook spokesperson speaking to AFP confirmed the database has been taken down and said: “We are looking into this issue, but believe this is likely information obtained before changes we made in the past few years to better protect people’s information”.

Facebook restricted the data in 2018, before that details such as check-ins, likes, photos, posts, videos, events, and groups, possibly the data scrapped before that.

It is unsure yet how the criminals obtained the data, but Comparitech says that “One possibility is that the data was stolen from Facebook’s developer API before the company restricted access to phone numbers in 2018”. Another possibility could be that “the data was stolen without using the Facebook API at all, and instead scraped from publicly visible profile pages”. Comparitech mentioned that having a user’s Facebook profile visibility set to “Public” makes it easier for criminals to scrape their data.

Knowing a person’s full name, Facebook profile, and phone number open up a whole host of abusive possibilities for hackers with malicious intent. Phishing campaigns are a common example of how to deploy this type of data.

Another way to take advantage of the available info is to launch large-scale SMS spamming campaigns. Remember, people are likely to click on a URL that they have received via SMS, so downloading a malware payload such as a banking Trojan, or visiting a well-crafted phishing page are the most prevalent dangers faced by the exposed individuals right now.

To prevent this scraping from happening again in the future,

  • Open Facebook and go to Settings
  • Click Privacy
  • Set all relevant fields to Friends or Only me
  • Set Do you want search engines outside of Facebook to link to your profile to No

It looks like Facebook users have no respite from data leaks. There have been multiple such incidents concerning the social media platform since the well-known Cambridge Analytica fiasco. The only real way to keep your personal information safe is to not put it out there on Facebook.

Source

Raja Rajan Avatar

Help Us Grow

If you like this post, please share it with your friends.

You are free to copy and redistribute this article in any medium or format, as long as you keep the links in the article or provide a link back to this page.

Subscribe to Newsletter




Privacy Settings

Privacy & Cookie Overview

Our website uses cookies to provide you with the best user experience possible. These cookies are stored in your browser and perform essential functions such as recognizing you when you return to our website, as well as helping us to understand which sections of the website you find most useful and engaging.

To learn more, you can read our Privacy & Cookie Policy or reach out through our Contact form.

Strictly Necessary Cookies

Strictly Necessary Cookies must always be enabled to ensure the proper functioning of this website and to allow us to provide you with excellent service. These cookies are also essential for saving your cookie preferences.

Google Adsense

We use Google AdSense to keep this site free by displaying relevant ads. AdSense requires essential cookies that cannot be disabled, but you can manage other cookies. We respect your privacy and provide options to control non-essential cookies.

For more details on how Google handles your data, visit Google's Data Usage Policy. Please review our Privacy Policy for more information on how we protect your data.

AddToAny

We use AddToAny for social sharing. It doesn’t store cookies, ensuring a privacy-friendly experience. AddToAny complies with GDPR and CCPA by default.

For more, see their Privacy Policy.

OneSignal

We use OneSignal to send notifications to users who opt in. OneSignal complies with GDPR and is certified under the EU-US and Swiss-US Privacy Shield frameworks.

For more, see their Privacy Policy.

3rd Party Cookies

This website utilizes third-party cookies, which can enhance your experience and support our ongoing efforts to improve our services.

Google Analytics

We use Google Analytics to collect anonymous data, such as visitor numbers and popular pages, to improve user experience and site performance. Keeping this cookie enabled helps us refine the site based on visitor activity.

For more information, see Google’s Privacy Policy.

Discover more from Prime Inspiration

Subscribe now to keep reading and get access to the full archive.

Continue reading