Facebook says ~100 app developers might have had improper access to Groups member data even after the company announced restrictions to Groups API last year
At least 11 accessed data in the last two months — Facebook says that even after it locked down its Groups system last year …
Context & Ripple Effects
Facebook has spent the past year-and-a-half trying to prove it can police its developer platform: the post-Cambridge Analytica review of apps with extended data access, the April 2018 lockdown requiring approval for every app touching the Groups, Pages, and Events APIs, and a purge that by September had removed tens of thousands of apps from about 400 developers. This disclosure is a stress test of that cleanup — roughly 100 developers may have kept improper access to Groups member data even after restrictions were announced, with at least 11 pulling data within the last two months.
First-order effects
- The ~100 affected developers face revoked access or removal under the same enforcement machinery Facebook used on its earlier app audit, and Groups members whose data was accessed are now part of another notification-and-disclosure cycle.
Second-order effects
- The finding undermines the credibility of Facebook's 2018 approval gate — if restricted APIs leaked data after lockdown, regulators auditing the Cambridge Analytica aftermath have fresh evidence that platform controls lag announcements.
Third-order effects
- A pattern of repeated post-lockdown leaks (the photo API bug exposed unshared photos from ~6.8M users months before this) points toward platform governance shifting from self-audit to externally enforced compliance for social graph data.
The trend: Platform API governance is moving from company-announced restrictions toward enforced audits, as each disclosed leak erodes trust that Facebook's own gates hold.