/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Facebook says the leaked 533M records are a different data set that attackers created by abusing a flaw in a Facebook contacts import feature, not by hacking

Wired Lily Hay Newman

Context & Ripple Effects

Days after a dataset of 533M Facebook users' records resurfaced online, the company is drawing a hard line: this was not a hack, but attackers abusing its contacts import feature to scrape profiles. The framing matters because Facebook has been here before — its 2018 vulnerability exposed 50M accounts to full takeover through three distinct bugs introduced a year earlier.

The distinction between 'hacked' and 'scraped' is now under pressure: follow-up reporting says researchers found Facebook had known for years about exploits similar to the contact-importer abuse behind the 533M records. If that holds, the company's preferred characterization becomes a liability rather than a defense.

First-order effects

  • Facebook's immediate move is reputational damage control: relabeling the 533M-record dump as feature abuse rather than a breach changes which disclosure obligations and breach-response expectations it argues apply.

Second-order effects

  • Researchers' claims that Facebook knew about similar contact-importer exploits for years force the company to defend not just this incident but its patching track record, handing ammunition to regulators already scrutinizing its data practices.

Third-order effects

  • If the pattern holds — the 2018 takeover bugs, then years-old scraping exploits surfacing as mass datasets — regulators and users may stop accepting the scraped-vs-hacked distinction, treating any large-scale feature-level data extraction as a reportable security failure.

The trend: Platforms increasingly reframe massive user-data exposures as abuse of legitimate features rather than breaches, while researchers and regulators grow less willing to honor that line.

Discussion

  • @mikko @mikko on x
    Facebook assures us that it's important that your phone number was not stolen from Facebook by hacking. It was stolen by scraping. https://twitter.com/...
  • @carolecadwalla Carole Cadwalladr on x
    I've been tweeting about latest Facebook breach because it seems to show it's learned nothing since Cambridge Analytica. It's refused to answer basic press inquiries. And now, it's pulled out rest of Cambridge Analytica playbook. This isn't FB's fault. It's ‘malicious actors’ 1/ …
  • @mikko @mikko on x
    How was Facebook scraped? Effectively, the attacker created an address book with every phone number on the planet and then asked Facebook if his ‘friends’ are on Facebook.
  • @ashk4n Ashkan Soltani on x
    Facebook confirms that a sample of the 533M data is related to a ‘contact importers vulnerability’ which was fixed in Aug 2019 While there was some reporting of a ‘contact importer vuln’ in 2019, @Facebook never actually disclosed any details or notified affected users (1/6) http…
  • @carolecadwalla Carole Cadwalladr on x
    It took Facebook 5 days to publish this. It's refusing to even acknowledge journalists's qs. It doesn't appear to be cooperating with the regulator. And these are not ‘facts’. This is a high-stakes PR op that blames Facebook's users for their shocking failure to protect them http…
  • @vmanancourt Vincent Manancourt on x
    .@laurenscerulus and I were able to contact a European head of state and a top EU Commissioner *directly* using details in the Facebook leak. Imagine what sophisticated scammers could do. https://www.politico.eu/...
  • @ashk4n Ashkan Soltani on x
    Also happening *now*. Someone (that I don't know) listening to the Spaces chat offered to demonstrate an SS7 exploit against my number to hijack my @PayPal account. (The attacker's phone number is fake) https://twitter.com/... https://twitter.com/...
  • @ashk4n Ashkan Soltani on x
    Not only is @Facebook past the indemnification period of the FTC settlement (June 12 2019), they also may have violated the terms of the settlement requiring them to report breaches of covered information (ht @JustinBrookman ) https://www.ftc.gov/... https://twitter.com/...
  • @rmac18 @rmac18 on x
    Just saw this explanation from Facebook about the data leak, which interestingly claims it's focused on protecting people because “scraping data” is against its terms of service. That's funny because FB has done nothing about Clearview AI scraping photos. https://t.co/K1vGX6icD6 …
  • @sarahfrier Sarah Frier on x
    This is so reminiscent of the days following the Cambridge Analytica news, during which Facebook just kept saying it wasn't a hack, and didn't apologize. That strategy didn't work for them then... https://twitter.com/...
  • @mikko @mikko on x
    For users who try to maintain an unlisted number, the distinction between hacking and scraping might not feel that important. Lots of politicians, celebrities and people with abusive ex-partners had their phone numbers exposed.
  • @caseynewton Casey Newton on x
    Truly heroic amount of work from @lilyhnewman to untangle which leaked Facebook data is part of this recent breach, which seems to be at odds with the company's statements so far. https://t.co/iA9Tn7HsQm
  • @abiaad Pierre Abi-aad on x
    My #Facebook account is closed and removed since 2015 but my phone number is part a data breach fixed in 2019. This is fucking scary. #privacy #breach https://twitter.com/...
  • @fboversight @fboversight on x
    Journalists from @Politico managed to contact a EU commissioner and a head of state via the Facebook data breach. “Imagine what sophisticated scammers could do” to any of the users involved in the leak. https://twitter.com/...
  • @daithaigilbert David Gilbert on x
    Facebook has addressed the leak of a database containing the phone numbers of 533 Million users. It's repsonse? It's not our fault, it's yours https://www.vice.com/...