Hackers publish private messages from 81K Facebook accounts and claim to have details from up to 120M accounts for sale; FB blames 3rd-party browser extensions
Andrei Zakharov / BBC :
Context & Ripple Effects
This lands weeks after Facebook disclosed that a three-bug flaw introduced in July 2017 let attackers act as if they were the account holder — so the company is answering a second exposure question within two months, and this time it points at third-party browser extensions rather than its own code.
The $0.10-per-account listing also previews what became a durable resale market: by 2020 a security firm bought a 267M-user database for £500 on the dark web, and in 2021 data on 533M Facebook users surfaced online, which Facebook attributed to a leak reported and fixed back in 2019.
First-order effects
- Buyers on the hacker forum can acquire details for up to 120M accounts at $0.10 each, while the roughly 81K account holders whose private messages were published face direct exposure of their conversations.
- Facebook's attribution to third-party browser extensions shifts the immediate remediation burden onto users running those add-ons rather than onto platform-side changes.
Second-order effects
- The listing helps establish a liquid secondary market for scraped Facebook data — the £500 later paid for 267M mostly-US records shows per-record value collapsing toward bulk-commodity pricing.
- Each successive dump forces Facebook into reactive attribution — bugs, then extensions, then an old fixed leak — giving regulators and researchers a pattern to contest the company's breach accounting against.
Third-order effects
- Across 2018–2021 the circulating scale grows from 120M to 267M to 533M records, suggesting aggregated Facebook identity data persists as a stockpile that individual fixes do not recall — a structural problem of already-scraped data rather than one-off breaches.
- If attribution keeps landing outside Facebook's own systems, pressure builds for oversight covering the whole data supply chain — browser extensions, scrapers, and brokers — not just the platforms where the data originated.
The trend: Facebook user data is becoming a persistently traded dark-web commodity, with each disclosed fix followed by ever-larger resurfaced dumps.