/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Hackers publish private messages from 81K Facebook accounts and claim to have details from up to 120M accounts for sale; FB blames 3rd-party browser extensions

Andrei Zakharov / BBC :

BBC Andrei Zakharov

Context & Ripple Effects

This lands weeks after Facebook disclosed that a three-bug flaw introduced in July 2017 let attackers act as if they were the account holder — so the company is answering a second exposure question within two months, and this time it points at third-party browser extensions rather than its own code.

The $0.10-per-account listing also previews what became a durable resale market: by 2020 a security firm bought a 267M-user database for £500 on the dark web, and in 2021 data on 533M Facebook users surfaced online, which Facebook attributed to a leak reported and fixed back in 2019.

First-order effects

  • Buyers on the hacker forum can acquire details for up to 120M accounts at $0.10 each, while the roughly 81K account holders whose private messages were published face direct exposure of their conversations.
  • Facebook's attribution to third-party browser extensions shifts the immediate remediation burden onto users running those add-ons rather than onto platform-side changes.

Second-order effects

  • The listing helps establish a liquid secondary market for scraped Facebook data — the £500 later paid for 267M mostly-US records shows per-record value collapsing toward bulk-commodity pricing.
  • Each successive dump forces Facebook into reactive attribution — bugs, then extensions, then an old fixed leak — giving regulators and researchers a pattern to contest the company's breach accounting against.

Third-order effects

  • Across 2018–2021 the circulating scale grows from 120M to 267M to 533M records, suggesting aggregated Facebook identity data persists as a stockpile that individual fixes do not recall — a structural problem of already-scraped data rather than one-off breaches.
  • If attribution keeps landing outside Facebook's own systems, pressure builds for oversight covering the whole data supply chain — browser extensions, scrapers, and brokers — not just the platforms where the data originated.

The trend: Facebook user data is becoming a persistently traded dark-web commodity, with each disclosed fix followed by ever-larger resurfaced dumps.