Third-party Facebook app by Cultura Colectiva left 540M+ records of users' info exposed on AWS; Amazon was notified in Jan., but data was online until recently
The UpGuard Cyber Risk team can now report that two more third-party developed Facebook app datasets have been found exposed to the public internet.
Context & Ripple Effects
This is the storage-layer sequel to the app-scraping scandals of 2018. After Cambridge Analytica, scrutiny focused on what third-party apps could pull out of Facebook — including the 2014 internal warning that Kogan's survey app could sell user data and the quiz-app ecosystem that followed it. UpGuard's find shows the other half of the pipeline: data those apps already copied, sitting misconfigured on someone else's infrastructure.
The detail that matters is the timeline: Amazon was notified in January, yet the Cultura Colectiva dataset stayed online until recently. That turns a Facebook developer-governance story into an AWS incident-response story, and it lands while Facebook is still cleaning up its own edges — it later had to admit roughly 100 app developers may have kept improper access to Groups member data even after API restrictions.
First-order effects
- Over 540 million people whose records sat in the Cultura Colectiva dataset were exposed to anyone who found the bucket, and Facebook now owns another round of questions about what its app ecosystem exported and where those copies live.
- Amazon's months-long gap between the January notification and takedown puts its abuse-report handling under direct scrutiny, since the shared-responsibility model leaves bucket owners — not AWS — as the party expected to act.
Second-order effects
- Facebook faces pressure to treat developer-held data copies as an auditable surface rather than a policy line, extending the cleanup pattern already visible in its Groups API restrictions and suspensions like CubeYou.
- Cloud rivals can position faster misconfiguration response as a differentiator, forcing AWS to justify why a reported exposure persisted for months after disclosure.
Third-order effects
- If the pattern holds, platform accountability extends beyond the API to wherever third parties store the data they extracted — meaning platforms need telemetry into downstream copies, and regulators may treat a leaky developer bucket as the platform's failure.
- Publicly readable cloud storage becomes a recurring breach class in its own right, pushing both cloud providers and enterprise buyers toward default-private configurations and automated exposure scanning.
The trend: Platform data governance is expanding from controlling what leaves the API to tracking where third-party copies end up, with cloud providers' response speed to reported exposures becoming the new bottleneck.