Study: Facebook lets ads target your account using info given for security purposes, like your phone number, as well as info from your friends' address books
Facebook Is Using Your Private Information … Seamus Bellamy / Boing Boing : Facebook's been caught using their customers' 2FA information to spam them with text ads John Glenday / The Drum : Extent of ‘shadow’ data Facebook hands to advertisers revealed after lengthy study Parmy Olson / Forbes : Facebook Is Committed To WhatsApp Encryption, But Could Bypass It Too Chris Burns / SlashGear : Facebook uses info you never provided to target you with ads Sergiu Gatlan / Softpedia News : Facebook Uses Your 2FA Phone Number for Ad Targeting MacDailyNews : Facebook is giving advertisers access to users' shadow contact information Levi Sumagaysay / Mercury News : Facebook targets ads using phone numbers submitted for security purposes J.M. Porup / ITworld.com : Hey Facebook: Quit discouraging people from using 2FA Christopher Baugh / iPhone in Canada Blog : Facebook Shares Users' ‘Shadow’ Contact Information With Advertisers: REPORT Ina Fried / Axios : Founders keep piling on Facebook Johnny Lieu / Mashable : Facebook allows advertisers to target you based on your shadow profile Tweets: Kashmir Hill / @kashhill : Facebook is using contact information you handed over for security purposes and contact information you didn't hand over at all to target you with ads. http://gizmodo.com/... Eric Mill / @konklone : Ugggghhh. Facebook confirms what @kashhill reported: Facebook is taking phone numbers given to them for two factor authentication and using them for ad targeting. Gross and completely irresponsible. https://gizmodo.com/... pic.twitter.com/TNpPUxsKz6 Eva / @evacide : I spend a lot of time trying to convince people to lock down their social media accounts with 2FA. Boy does this undermine my efforts. http://twitter.com/... Anil Dash / @anildash : It's hard to overstate how irresponsible it is to use *security* features like two-factor authentication as a wedge to target ads. Abusing features that are meant to increase user safety & security is an indication of a fundamentally untrustworthy product decision-making process. http://twitter.com/... Kashmir Hill / @kashhill : That thing where you go to a company and ask if they do something and they are like 'no way.'And then some academic researchers perform extensive testing to see if company does that thing. And then company is like, 'oh yeah, we do that thing.'http://gizmodo.com/... Trevor Timm / @trevortimm : “When a user gives Facebook a phone number for two-factor authentication or in order to receive alerts about new log-ins to a user's account, that phone number became targetable by an advertiser within a couple of weeks.” http://gizmodo.com/... @briankrebs : Being in infosec for so long takes its toll. I've come to the conclusion that if you give a data point to a company, they will eventually sell it, leak it, lose it or get hacked and relieved of it. There really don't seem to be any exceptions, and it gets depressing. Patrick Beuth / @patrickbeuth : “People own their address books,” a Facebook spokesperson said by email. “We understand that in some cases this may mean that another person may not be able to control the contact information someone else uploads about them.” http://twitter.com/... Tom Gara / @tomgara : This is so crazy: even if you deliberately don't include your mobile number in your Facebook profile, they'll harvest it when you use it for two-factor authentication, and let advertisers target you with it. https://gizmodo.com/... pic.twitter.com/TigHlGR2zF Miriam Elder / @miriamelder : Abusing the trust of people who go the extra step to care about security feels like a new low. http://twitter.com/... Noah Smith / @noahpinion : When Congress eventually gets around to passing a comprehensive data privacy bill, this sort of thing will surely be illegal. http://twitter.com/... Karen.Yeo / @souterrain : Reminder that facebook never apologised to folks like me (thanks to whichever friend who downloaded Aleksandr Kogan's app) whose accounts were accessed. #CambridgeAnalytica #privacy http://twitter.com/... Will Oremus / @willoremus : I thought about this when I signed up for 2fa on Facebook and then I was like, “Naaah, they'd never do that, that would be too blatant. right?” Wrong. https://twitter.com/... Paresh Dave / @peard33 : Facebook says it let's you control ads experience but then... “It's likely that he was shown the ad because someone else uploaded his contact information via contact importer” and he can't do anything about it. http://twitter.com/... Barton Gellman / @bartongellman : This is why you should not say yes when an app asks for access to your address book. You are breaching the privacy of every one of your contacts. I never gave Facebook my cell phone, but someone I know surely did. Now Facebook lets advertisers find me with that number. http://twitter.com/... John Paczkowski / @johnpaczkowski : Shameless: Once a user gives Facebook a phone number for two-factor authentication ... that phone number became targetable by an advertiser within a couple of weeks. http://twitter.com/... Gabriel Dance / @gabrieldance : great reporting showing that @facebook in fact does keep shadow profiles on users. something they have long denied. http://twitter.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb : “[Facebook] users who want their accounts to be more secure are forced to make a privacy trade-off and allow advertisers to more easily find them on the social network.” - @kashhill https://gizmodo.com/... Neil Greenberg / @ngreenberg : “This means that the junk email address that you hand over for discounts or for shady online shopping is likely associated with your account and being used to target you with ads.” https://gizmodo.com/... Mikael Thalen / @mikaelthalen : Facebook is serving users ads based on information, including phone numbers, they never provided https://gizmodo.com/... pic.twitter.com/PateXcySdp Hugo Jonker / @hugojonker : A piece by @kashhill: she ran an ad on facebook, aiming to target a user via data he had never shared with FB. Few hours later, he was shown the ad. Unfortunately, not the worst of the revelations in this story. https://gizmodo.com/... (thanks @kashhill for the PETS paper link) Kenn White / @kennwhite : “Facebook did not dispute any of the researchers' findings.” https://twitter.com/... Deepa Seetharaman / @dseetharaman : This is fascinating reporting by @kashhill. Here's her story: https://gizmodo.com/... Here's the study she references: https://mislove.org/... Ellen Huet / @ellenhuet : if you remove your phone # from fb, it emails you telling you it turned off 2FA, and that to turn 2FA back on you have to add a new #. doesn't prompt you about the other option, using an authenticator app http://twitter.com/...
Context & Ripple Effects
This study lands at the center of a data-supply chain Facebook built long before anyone audited its inputs: as early as presidential campaigns uploading voter files and email lists, advertisers were matching their own contact lists against Facebook's graph, and the platform quietly widened what could be matched. The finding that phone numbers handed over for two-factor authentication — a security control, not a marketing consent — feed the same targeting pipeline collapses the line between data users gave Facebook to protect themselves and data they gave it to be sold against.
The second half of the finding is more corrosive than the first: even people who never gave Facebook their number can be targeted through their friends' uploaded address books, meaning opting out individually is structurally impossible. That shadow-data exposure is exactly what Facebook's later advertiser-transparency tool was built to answer — and reporting found that tool nearly unusable for a normal person trying to trace which list contained them.
First-order effects
- Users who enabled two-factor authentication with a phone number are directly affected: the number they provided for account security is available to advertisers as a targeting key, and there is no setting that separates the two uses.
- Advertisers gain a matchable identifier for people who never consented to be marketed to, since any friend's contact-list upload makes a non-user's or privacy-conscious user's number addressable.
Second-order effects
- Facebook's transparency obligations sharpen: once researchers showed the scope of 'shadow' contact data, the company had to expose which advertisers used a user's information — and the resulting tool proved so hard to interpret that disclosure became a compliance artifact rather than an actual remedy.
- Rival platforms face the same audit: if security-provided identifiers are fair game for ad matching on Facebook, researchers and regulators have a template for testing whether the same practice exists elsewhere, raising the cost of every 'we only use your number for login' claim.
Third-order effects
- If the pattern holds, the durable fix is structural rather than per-user: purpose limitation rules that legally separate security credentials from advertising data, turning what was a terms-of-service question into a regulatory one.
- Contact-list uploading itself becomes the contested mechanism — the same feature that powered campaign voter-file matching and friend-graph growth is what made non-consensual targeting possible, so platforms face pressure to treat uploaded third-party contacts as radioactive rather than an asset.
The trend: Platform data practices are moving from opaque matching of whatever users and their friends supply toward forced disclosure and purpose-limitation rules, with each researcher exposé narrowing what companies can quietly repurpose.