Data of 267 million Facebook users leaked online

Agencies
December 21, 2019

A database containing personal details of more than 267 million Facebook users was allegedly left exposed on the web, according to a report from Britain-based tech research firm Comparitech and security researcher Bob Diachenko.

Diachenko believes the trove of data -- including Facebook user IDs, phone numbers and names -- is most likely the result of an illegal scraping operation or Facebook API abuse by criminals in Vietnam.

"Scraping" is a term used to describe a process in which automated bots quickly sift through large numbers of web pages, copying data from each one into a database.

The information contained in the database could be used to conduct large-scale SMS spam and phishing campaigns, among other threats to end users, said the report on Thursday, adding that most of the affected users were from the US.

Facebook is reportedly investigating the issue.

"We are looking into this issue, but believe this is likely information obtained before changes we made in the past few years to better protect people's information," a Facebook spokesperson told Engadget.

The revelations come at a time when Facebook is trying to regain the trust of its users with protection of their data following the Cambridge Analytica scandal that badly hit its reputation.

More than one and a half years after the Cambridge Analytica scandal first became public, the US Federal Trade Commission (FTC) earlier this month said that the now-defunct British data analytics and consulting company engaged in deceptive practices to harvest personal information from tens of millions of Facebook users for voter profiling and targeting.

After discovering that personal details of 267 million Facebook users were exposed online, Diachenko notified the Internet service provider managing the IP address of the server so that access could be removed.

However, the data was also posted to a hacker forum as a download, said the security researcher.

Facebook IDs are unique, public numbers associated with specific accounts, which can be used to discern an account's username and other profile info.

While how criminals obtained the user IDs and phone numbers is not entirely clear, one possibility is that the data was stolen from Facebook's developer API before the company restricted access to phone numbers in 2018.

Facebook's API is used by app developers to add social context to their applications by accessing users' profiles, friends list, groups, photos and event data. Phone numbers were available to third-party developers prior to 2018.

Facebook's API could also have a security hole that would allow criminals to access user IDs and phone numbers even after access was restricted, Diachenko said.

Another possibility is that the data was stolen without using the Facebook API at all, and instead scraped from publicly visible profile pages, according to the report.

This isn't the first time such a database has been exposed. In September 2019, 419 million records across several databases were exposed, including phone numbers and Facebook IDs.

The report warned that Facebook users should be on the lookout for suspicious text messages.

Even if the sender knows your name or some basic information about you, be sceptical of any unsolicited messages, it added.

Comments

Helpful info. Lucky me I found your site by accident, and I'm stunned why this coincidence didn't happened in advance!
I bookmarked it.

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
March 25,2020

Moscow, Mar 25: An earthquake measuring 7.5 on the Richter scale struck off Russia's Kuril Islands on Wednesday, the United States Geological Survey (USGS) said.

The magnitude of the quake, which occurred at 2:49 am (UTC), was registered at a depth of 56.7 kilometres, about 219 kilometres southeast of the Russian town of Severo-Kuril'sk, the USGS said.

There were no immediate reports of casualties or damage to the property as a result of the quake.
Further details are awaited.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 27,2020

Kabul, Jan 27: A passenger plane crashed on Monday in a Taliban-held area of Afghanistan's Ghazni province, local officials said.

Arif Noori, spokesman for the provincial governor, said the plane went down around 1:10 p.m. local time in Deh Yak district, which is held by the Taliban. Two provincial council members also confirmed the crash.

The number of people on board and their fate was not immediately known, nor was the cause of the crash.

Ariana Airlines, Afghanistan's national carrier, dismissed the claim that one of their planes had crashed in a statement on their website, saying all their aircraft were operational and safe.

The mountainous Ghazni province sits in the foothills of the Hindu Kush mountains and is bitterly cold in winter.

The last major commercial air crash in Afghanistan occurred in 2005 when a Kam Air flight from western Herat to the capital Kabul crashed into the mountains as it tried to land in snowy weather.

The war however has seen a number of deadly crashes of military aircraft. One of the most spectacular occurred in 2013 when an American Boeing 747 cargo jet crashed shortly after takeoff from Bagram air base north of Kabul en route to Dubai in the United Arab Emirates. All seven crew member were killed.

Afghanistan's aviation industry suffered desperately during the rule of the Taliban when its only airline Ariana was subject to punishing sanctions and allowed to fly only to Saudi Arabia for Hajj flights.

Since the overthrow of the religious regime smaller private airlines have emerged but the industry is still a nascent one.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
January 6,2020

The Cambridge Analytica scandal is far from over. New explosive details leaked by a whistleblower shows that the extent of the rot is far deeper than previously thought.

An anonymous Twitter account, @HindsightFiles, has started releasing the documents, apparently on behalf of Brittany Kaiser, a former employee of the now defunct British data analytics and consulting company Cambridge Analytica.

"Democracies around the world are being auctioned to the highest bidder. We release the documents that explain how," reads the biography of the @HindsightFiles.

The document will reveal previously unreleased emails, project plans, case studies, negotiations and more spanning over 60 countries.

"Over the past two years I have given evidence to investigators, journalists and academics to analyse what happened at Cambridge Analytica, and how our data was used to influence democracies around the world. In the name of shedding light on these dark practices, I am releasing documents and emails in full for the public good," Kaiser, who worked with Cambridge Analytica from 2014 to 208, was quoted as saying.

"I do this to strengthen the case for data rights and enforcement of our electoral laws online globally. We should all be seeking more ethical digital future for ourselves and our children," added Kaiser who starred in the Oscar-shortlisted Netflix documentary "The Great Hack".

The details released so far includes links to material on the firm's activities in Malaysia, Kenya, Brazil and Iran, an addition to the John Bolton archive.

Over the next months, more than 100,000 documents relating to work in 68 countries are set to be released, according to a report in The Guardian.

More than one and a half year after the Cambridge Analytica scandal first became public, US regulators last month said that the now-defunct British data analytics and consulting company engaged in deceptive practices to harvest personal information from tens of millions of Facebook users for voter profiling and targeting.

According to Kaiser, the Facebook data scandal was part of a much bigger global operation designed to manipulate people in collaboration with governments, intelligence agencies, commercial companies and political campaigns.

The unpublished documents contain material that suggests the firm collaborated with a political party in Ukraine in 2017 even while under investigation as part of Robert Mueller's investigation into Russian interference in the 2016 US presidential election, said The Guardian report.

"There are emails between these major Trump donors discussing ways of obscuring the source of their donations through a series of different financial vehicles. These documents expose the entire dark money machinery behind US politics," Kaiser was quoted as saying.

Similar tactics were deployed in other countries that Cambridge Analytica operated in, including Britain, she claimed.

The files released by Kaiser suggest that Cambridge Analytica offered to help United Malays National Organisation (Umno), the party of Malaysia's Former Prime Minister Najib Razak, to influence the voting of 40 parliamentary constituencies in the 14th General Election (GE14) in 2013.

Umno, according to the leaks, requested the company to prepare a proposal to regain 13 seats, The South China Morning Post reported on Saturday.

In 2018, Razak claimed that he had never engaged Cambridge Analytica in any way.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.