Facebook says the leaked 533M records are a different data set that attackers created by abusing a flaw in a Facebook contacts import feature, not by hacking
WiredLily Hay Newman
Context & Ripple Effects
Days after a dataset of 533MFacebook users' records resurfaced online, the company is drawing a hard line: this was not a hack, but attackers abusing its contacts import feature to scrape profiles. The framing matters because Facebook has been here before — its 2018 vulnerability exposed 50M accounts to full takeover through three distinct bugs introduced a year earlier.
The distinction between 'hacked' and 'scraped' is now under pressure: follow-up reporting says researchers found Facebook had known for years about exploits similar to the contact-importer abuse behind the 533M records. If that holds, the company's preferred characterization becomes a liability rather than a defense.
First-order effects
Facebook's immediate move is reputational damage control: relabeling the 533M-record dump as feature abuse rather than a breach changes which disclosure obligations and breach-response expectations it argues apply.
Second-order effects
Researchers' claims that Facebook knew about similar contact-importer exploits for years force the company to defend not just this incident but its patching track record, handing ammunition to regulators already scrutinizing its data practices.
Third-order effects
If the pattern holds — the 2018 takeover bugs, then years-old scraping exploits surfacing as mass datasets — regulators and users may stop accepting the scraped-vs-hacked distinction, treating any large-scale feature-level data extraction as a reportable security failure.
The trend: Platforms increasingly reframe massive user-data exposures as abuse of legitimate features rather than breaches, while researchers and regulators grow less willing to honor that line.
Facebook assures us that it's important that your phone number was not stolen from Facebook by hacking. It was stolen by scraping. https://twitter.com/...
I've been tweeting about latest Facebook breach because it seems to show it's learned nothing since Cambridge Analytica. It's refused to answer basic press inquiries. And now, it's pulled out rest of Cambridge Analytica playbook. This isn't FB's fault. It's ‘malicious actors’ 1/ …
How was Facebook scraped? Effectively, the attacker created an address book with every phone number on the planet and then asked Facebook if his ‘friends’ are on Facebook.
Facebook confirms that a sample of the 533M data is related to a ‘contact importers vulnerability’ which was fixed in Aug 2019 While there was some reporting of a ‘contact importer vuln’ in 2019, @Facebook never actually disclosed any details or notified affected users (1/6) http…
It took Facebook 5 days to publish this. It's refusing to even acknowledge journalists's qs. It doesn't appear to be cooperating with the regulator. And these are not ‘facts’. This is a high-stakes PR op that blames Facebook's users for their shocking failure to protect them http…
.@laurenscerulus and I were able to contact a European head of state and a top EU Commissioner *directly* using details in the Facebook leak. Imagine what sophisticated scammers could do. https://www.politico.eu/...
Also happening *now*. Someone (that I don't know) listening to the Spaces chat offered to demonstrate an SS7 exploit against my number to hijack my @PayPal account. (The attacker's phone number is fake) https://twitter.com/... https://twitter.com/...
Not only is @Facebook past the indemnification period of the FTC settlement (June 12 2019), they also may have violated the terms of the settlement requiring them to report breaches of covered information (ht @JustinBrookman ) https://www.ftc.gov/... https://twitter.com/...
Just saw this explanation from Facebook about the data leak, which interestingly claims it's focused on protecting people because “scraping data” is against its terms of service. That's funny because FB has done nothing about Clearview AI scraping photos. https://t.co/K1vGX6icD6 …
This is so reminiscent of the days following the Cambridge Analytica news, during which Facebook just kept saying it wasn't a hack, and didn't apologize. That strategy didn't work for them then... https://twitter.com/...
For users who try to maintain an unlisted number, the distinction between hacking and scraping might not feel that important. Lots of politicians, celebrities and people with abusive ex-partners had their phone numbers exposed.
Truly heroic amount of work from @lilyhnewman to untangle which leaked Facebook data is part of this recent breach, which seems to be at odds with the company's statements so far. https://t.co/iA9Tn7HsQm
My #Facebook account is closed and removed since 2015 but my phone number is part a data breach fixed in 2019. This is fucking scary. #privacy #breach https://twitter.com/...
Journalists from @Politico managed to contact a EU commissioner and a head of state via the Facebook data breach. “Imagine what sophisticated scammers could do” to any of the users involved in the leak. https://twitter.com/...
Facebook has addressed the leak of a database containing the phone numbers of 533 Million users. It's repsonse? It's not our fault, it's yours https://www.vice.com/...