Net Interop Corp.

267M Facebook Users Had Name, Photos Numbers Leaked On Dark Web

By Interop inc - December 24, 2019 pasted in News

267M Facebook Users Had Names, Phone Numbers Leaked On Dark Web

Hundreds of millions of Facebook users' data has been found exposed on a database accessible on the dark web.

Compartech and security researcher Bob Diachenko reported that a database containing 267 million Facebook user IDs, phone numbers, and names was left exposed on the dark web without password protection or any authentication.

Dark Web Discovery

In total, 267,140,436 records were found exposed.

  • Facebook User IDs
  • Phone Numbers
  • Full Names

According to Diachenko, who examined the evidence, the data likely came from “an illegal scraping operation or Facebook API abuse by criminals in Vietnam.” Most of the stolen data belonged to users in the United States.

Illegal Scraping Operation

"Scaping is an Illegal scraping operation or Facebook API abuse by criminals in Vietnam."

Comparitech said that “‘scraping’ is a term used to describe a process in which automated bots quickly sift through large numbers of web pages, copying data from each one into a database. It’s difficult for Facebook and other social media sites to prevent scraping because they often cannot tell the difference between a legitimate user and a bot. Scraping is against Facebook’s–and most other social networks’–terms of service.”

While the information stolen was minimal, it could still potentially lead to large-scale SMS spam and phishing campaigns, among other threats to Facebook users whose data was compromised.

Facebook’s Investigation

While the information was taken, it may help to limit tracking, plug gaps, and scale SMS spam and phishing campaigns, such as targeting threats to Facebook against data.

Precautionary Measures

The database has since been taken offline. Users are advised to secure their accounts and change passwords if they were affected by this breach.