/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Facebook says it did not notify users about the 2019 data leak affecting 533M accounts at the time and doesn't plan to do so now

(Reuters) - Facebook Inc did not notify the more than 530 million users whose details were obtained through the misuse of a feature before 2019 and recently …

Reuters Elizabeth Culliford

Context & Ripple Effects

Facebook's decision follows a record in the related coverage of data-misuse warnings: it acknowledged having ignored an auditor's warning about device-partner access, while a 2018 filing anticipated further incidents on the scale of Cambridge Analytica.

The newly surfaced records also fit researchers' account that Facebook had known for years about similar contact-importer exploitation. The significance is not only the exposed data, but Facebook's choice to leave affected accounts without a direct notice.

First-order effects

  • More than 530 million affected Facebook users will not receive a company notification that could alert them to the exposure of their details.
  • Facebook makes its non-notification stance part of the incident response, alongside its acknowledgement that the feature misuse occurred before 2019.

Second-order effects

  • Ireland's Data Protection Commission's investigation of the 533 million-account leak puts the underlying exposure under formal regulatory scrutiny, regardless of Facebook's decision not to contact users.
  • The repeated record of warnings and similar exploits increases pressure on Facebook to show that data-access features are monitored and remediated before scraped data surfaces publicly.

Third-order effects

  • If regulators treat feature misuse and delayed disclosure as connected governance failures, platform privacy oversight will increasingly center on both preventive controls and post-incident notification practices.
  • The pattern points toward a stricter permission boundary for contact and other user-data access mechanisms, with platform operators bearing more responsibility for foreseeable scraping paths.

The trend: Large platforms are facing privacy scrutiny that increasingly links data-access design, known exploitation risks, and the adequacy of their incident disclosures.

Discussion

  • @epro Emil Protalinski on x
    Facebook did not comply with laws around the world that require disclosing such data leaks because it calculated that paying the fines, if and when they came, would cost less than the negative press resulting from notifying 533 million affected users. https://twitter.com/...
  • @tiffanycli Tiffany C. Li on x
    I'm confused. Did all 50 state data breach notification laws suddenly stop existing, and also the FTC stopped existing, and the GDPR stopped existing too? Because that's the only scenario where this doesn't land Facebook in a heap of legal trouble. https://www.reuters.com/...
  • @jason_kint Jason Kint on x
    We're up to a couple hundred people in this Twitter Space including the technologists who discovered the Facebook vulnerability, the 500 million personal data records, and others who have spent careers trying to get Facebook to be a better company. https://twitter.com/... https:/…
  • @jason_kint Jason Kint on x
    This here says everything you need to know about the FTC and SEC walking away from dealing with the real problem in 2019. Now the question will be whether the $5 billion from the settlement has still has some juice to make this go away, too. https://twitter.com/...
  • @jason_kint Jason Kint on x
    It included their phone numbers and according to reports it included non-public phone numbers used for lost passwords and two-factor authentication! But they're not going to tell anyone???!?!? https://twitter.com/...
  • @stickermule @stickermule on x
    FACEBOOK is trying very hard to cover up their latest scandal and failing very badly!
  • @varunjuice Varun Singh on x
    Zero surprise that the root cause for this traces back to the Growth team - the most cavalier perhaps of all teams at FB. https://twitter.com/...
  • @ashk4n Ashkan Soltani on x
    Telling insights from a former @Facebook PM 👇 PPL I've talked to / cases I've worked on repeatedly point to the growth teams as the root cause of many of the past privacy disasters at @Google & @Facebook I've said before: “growth at any cost” is the new “unsafe at any speed” http…
  • @matthew_d_green Matthew Green on x
    Remembering when Facebook started collecting phone numbers “for 2FA purposes” and how well that worked out. https://twitter.com/...
  • @tonyajoriley Tonya Riley on x
    Facebook will NOT notify users if their data was included in a massive breach, Reuters reports. Seems like something that will come up when Congress finally has a hearing dedicated to data breaches https://www.reuters.com/... https://twitter.com/...
  • @astepanovich Amie Stepanovich on x
    I've been saying for a long time — too long — that our data breach laws are too narrow and don't cover nearly enough information. Most (not all) are far too tied to financial info or gov identifiers. In the social media age we need to greatly expand our thinking. https://twitter.…
  • @carolecadwalla Carole Cadwalladr on x
    ‘Facebook is trying to frame this as a ‘scrape’ not a ‘hack’ but this is completely misleading. It revealed non-public information. It linked phone numbers to profiles. And that was private information’- @ashk4n
  • @matthew_d_green Matthew Green on x
    I'm not going to say that Facebook's totally stupid treatment of that identifier set back customer security by a decade but maybe five years?
  • @jason_kint Jason Kint on x
    A bit of an understatement, “This is not the first time Facebook's $80 billion advertising arm has potentially profited from hate or extremism.” Congrats marketers. https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    Good on them! The bigger the arrogance, the bigger the fine https://twitter.com/...
  • @grady_booch Grady Booch on x
    Facebook is a profoundly unethical- and increasingly incompetent- organization, and it starts at the top, with Mark. https://www.reuters.com/...
  • @profcarroll David Carroll on x
    Why the Facebook contact uploader vulnerability and subsequent hackbreachleak matters. Phone numbers are the ideal attack surface to force multiply other vulnerabilities. Facebook exposed non-public information and needs to answer for it. https://twitter.com/...
  • @slpng_giants @slpng_giants on x
    This was phenomenal. @facebook may be good at obfuscation, but the sheer numbers of smart, knowledgeable people who are on to them is staggering. https://twitter.com/...
  • @intidc Inti De Ceukelaire on x
    This was a historical call. Journalists from different agencies, regulators and tech experts exchanging info on the same story they're covering. Teaming up instead of allowing Facebook's toxic PR comms to divide them. https://twitter.com/...
  • @profcarroll David Carroll on x
    Wow. @intdc explains how Facebook silently changing its confusing privacy settings set the stage for this catastrophic leak by making it too difficult to realize the difference between the visibility of your phone number vs. lookup by phone number. Cambridge Analytica déjà vu.
  • @jason_kint Jason Kint on x
    ok, we're at point where Facebook seems focused on fragmenting info re: this data leak - it's hard to keep track of what's what - *a perfect case to light up Twitter Spaces.* I'm going to go live shortly @12pm ET - welcome anyone interested in listening, sharing notes, questions.…
  • @profcarroll David Carroll on x
    Facebook revealed non-public information. Case closed. Don't let them spin this with gas lighting you on hack, breach, leak, nonsense.
  • @mikko @mikko on x
    Facebook assures us that it's important that your phone number was not stolen from Facebook by hacking. It was stolen by scraping. https://twitter.com/...
  • @carolecadwalla Carole Cadwalladr on x
    I've been tweeting about latest Facebook breach because it seems to show it's learned nothing since Cambridge Analytica. It's refused to answer basic press inquiries. And now, it's pulled out rest of Cambridge Analytica playbook. This isn't FB's fault. It's ‘malicious actors’ 1/ …
  • @mikko @mikko on x
    How was Facebook scraped? Effectively, the attacker created an address book with every phone number on the planet and then asked Facebook if his ‘friends’ are on Facebook.
  • @ashk4n Ashkan Soltani on x
    Facebook confirms that a sample of the 533M data is related to a ‘contact importers vulnerability’ which was fixed in Aug 2019 While there was some reporting of a ‘contact importer vuln’ in 2019, @Facebook never actually disclosed any details or notified affected users (1/6) http…
  • @carolecadwalla Carole Cadwalladr on x
    It took Facebook 5 days to publish this. It's refusing to even acknowledge journalists's qs. It doesn't appear to be cooperating with the regulator. And these are not ‘facts’. This is a high-stakes PR op that blames Facebook's users for their shocking failure to protect them http…
  • @vmanancourt Vincent Manancourt on x
    .@laurenscerulus and I were able to contact a European head of state and a top EU Commissioner *directly* using details in the Facebook leak. Imagine what sophisticated scammers could do. https://www.politico.eu/...
  • @ashk4n Ashkan Soltani on x
    Also happening *now*. Someone (that I don't know) listening to the Spaces chat offered to demonstrate an SS7 exploit against my number to hijack my @PayPal account. (The attacker's phone number is fake) https://twitter.com/... https://twitter.com/...
  • @ashk4n Ashkan Soltani on x
    Not only is @Facebook past the indemnification period of the FTC settlement (June 12 2019), they also may have violated the terms of the settlement requiring them to report breaches of covered information (ht @JustinBrookman ) https://www.ftc.gov/... https://twitter.com/...
  • @rmac18 @rmac18 on x
    Just saw this explanation from Facebook about the data leak, which interestingly claims it's focused on protecting people because “scraping data” is against its terms of service. That's funny because FB has done nothing about Clearview AI scraping photos. https://t.co/K1vGX6icD6 …
  • @sarahfrier Sarah Frier on x
    This is so reminiscent of the days following the Cambridge Analytica news, during which Facebook just kept saying it wasn't a hack, and didn't apologize. That strategy didn't work for them then... https://twitter.com/...
  • @mikko @mikko on x
    For users who try to maintain an unlisted number, the distinction between hacking and scraping might not feel that important. Lots of politicians, celebrities and people with abusive ex-partners had their phone numbers exposed.
  • @caseynewton Casey Newton on x
    Truly heroic amount of work from @lilyhnewman to untangle which leaked Facebook data is part of this recent breach, which seems to be at odds with the company's statements so far. https://t.co/iA9Tn7HsQm
  • @abiaad Pierre Abi-aad on x
    My #Facebook account is closed and removed since 2015 but my phone number is part a data breach fixed in 2019. This is fucking scary. #privacy #breach https://twitter.com/...
  • @fboversight @fboversight on x
    Journalists from @Politico managed to contact a EU commissioner and a head of state via the Facebook data breach. “Imagine what sophisticated scammers could do” to any of the users involved in the leak. https://twitter.com/...
  • @daithaigilbert David Gilbert on x
    Facebook has addressed the leak of a database containing the phone numbers of 533 Million users. It's repsonse? It's not our fault, it's yours https://www.vice.com/...