Facebook's subtle disclosure about storing millions of Instagram passwords in plain text before a holiday weekend shows it has mastered the art of the news dump
the data was also utilised to “improve ads.” Rob Price / @robaeprice : NEW: Facebook's harvesting of 1.5 million users' email contact data without consent may have broken US and EU law, experts say. Facebook's actions could have violated GDPR, as well as the FTC consent decree. https://www.businessinsider.com/ ... Rob Price / @robaeprice : If regulators decided to take action against Facebook for slurping up users' contacts it would open up a fresh legal headache for the scandal-ridden company. The Irish data watchdog has said it's already talking to Facebook about this. https://twitter.com/... @i_do_tech_stuff : LinkedIn: I'm going to try and scrape user email contacts EVERY TIME they sign in. Facebook: Hold my beer. Rob Price / @robaeprice : SCOOP: Facebook harvested 1.5 million people's email contacts without their consent. It says it “unintentionally uploaded” them after asking users for their email passwords. http://www.businessinsider.com/ ... @saranormous : If true, this is insane. Password harvesting isn't something you can “unintentionally” do at scale — roadmap, code, code review, deployment, use of the contacts data, and no one stopped this? http://twitter.com/... Dare Obasanjo / @carnage4life : How do you unintentionally write & ship code that asks users for their email password, scans their address book then uploads their contacts to your server without asking permission?For Facebook “unintentional” always means “we got caught? aw shucks”. 🤷🏾♂ ️ http://www.businessinsider.in/ ... Rob Price / @robaeprice : It's worth noting that while 1.5 million users' contact books were *directly* harvested, the total number of people whose contact details were obtained may well be in the dozens/hundreds of millions, as people often have hundreds of contacts. http://twitter.com/...
Context & Ripple Effects
The story has a two-step arc. In March, Facebook [[a:939730|said it would notify hundreds of millions of Facebook users and thousands of Instagram users]] after finding passwords stored in a readable format — a disclosure that framed Instagram exposure as marginal. A month later, it quietly updated its March blog post to say the Instagram count was millions, not tens of thousands, and CNN flags that both revisions landed before a holiday weekend.
The timing matters because Facebook is already in regulators' crosshairs on data handling: experts say its harvesting of 1.5 million users' email contacts without consent — data used to 'improve ads' — may violate GDPR and the FTC consent decree, and the Irish data watchdog says it is talking to Facebook about it. Each understated disclosure now feeds directly into live enforcement conversations.
First-order effects
- Affected Instagram users face another credential-hygiene burden — the second plaintext-password episode in six months, following a November bug that sent some Instagram users their own passwords in plaintext URLs.
- Facebook's credibility problem is now internal as well as external: its own corrected blog post shows the company's initial incident estimates cannot be taken at face value.
Second-order effects
- Regulators already engaged with Facebook — the FTC via its consent decree and Irish authorities via GDPR — gain concrete evidence that the company's self-reported breach scopes shrink on first pass and expand later, strengthening the case for action rather than negotiated remediation.
- Competing platforms inherit a messaging burden: every future security notice will be read against Facebook's pattern of Friday-afternoon corrections, pressuring the industry toward more conservative initial disclosures.
Third-order effects
- If the pattern holds — quiet disclosure, revised numbers, holiday timing — expect pressure for mandated external audits or standardized breach-notification rules that remove the disclosing company from controlling its own scope estimates, a structural shift in how platform data incidents reach the public.
The trend: Platform self-disclosure of security failures is becoming an adversarial act: companies release minimal estimates on low-news cycles, then revise upward, accelerating the shift toward regulator-driven verification of breach claims.