Facebook says it did not notify users about the 2019 data leak affecting 533M accounts at the time and doesn't plan to do so now
(Reuters) - Facebook Inc did not notify the more than 530 million users whose details were obtained through the misuse of a feature before 2019 and recently …
Context & Ripple Effects
Facebook's decision follows a record in the related coverage of data-misuse warnings: it acknowledged having ignored an auditor's warning about device-partner access, while a 2018 filing anticipated further incidents on the scale of Cambridge Analytica.
The newly surfaced records also fit researchers' account that Facebook had known for years about similar contact-importer exploitation. The significance is not only the exposed data, but Facebook's choice to leave affected accounts without a direct notice.
First-order effects
- More than 530 million affected Facebook users will not receive a company notification that could alert them to the exposure of their details.
- Facebook makes its non-notification stance part of the incident response, alongside its acknowledgement that the feature misuse occurred before 2019.
Second-order effects
- Ireland's Data Protection Commission's investigation of the 533 million-account leak puts the underlying exposure under formal regulatory scrutiny, regardless of Facebook's decision not to contact users.
- The repeated record of warnings and similar exploits increases pressure on Facebook to show that data-access features are monitored and remediated before scraped data surfaces publicly.
Third-order effects
- If regulators treat feature misuse and delayed disclosure as connected governance failures, platform privacy oversight will increasingly center on both preventive controls and post-incident notification practices.
- The pattern points toward a stricter permission boundary for contact and other user-data access mechanisms, with platform operators bearing more responsibility for foreseeable scraping paths.
The trend: Large platforms are facing privacy scrutiny that increasingly links data-access design, known exploitation risks, and the adequacy of their incident disclosures.
Related: Public-data permission boundary · Ecosystem cyber defense · Facebook · Facebook ignored auditor data-use warnings · Researchers cite similar Facebook scraping exploits
Related Coverage
- Facebook Says It's Your Fault That Hackers Got Half a Billion User Phone Numbers VICE · David Gilbert
- Despite A Ban, Facebook Continued To Label People As Interested In Militias For Advertisers BuzzFeed News · Ryan Mac
- View article Forbes
- Facebook will tell you if a page is satire, but not if your data was leaked 9to5Mac · Ben Lovejoy
- Facebook isn't planning to tell you if you're one of the 533 million people whose data leaked The Verge · Mitchell Clark
- ‘Misleading’ Facebook data leak claims questioned Politico · Vincent Manancourt
- View article Neowin
- Facebook won't tell you if you were caught up in its data breach TechRadar · Joel Khalili
- How To Check If You Were A Part Of The 533 Million Facebook Data Leak? fossbytes.com · Charanjeet Singh
- Facebook won't even tell you if your data was compromised in the massive breach BGR · Chris Smith
- Concerns emerge about Facebook's disclosure of user data breach SiliconANGLE · Maria Deutscher
- Facebook says data from 530M users was obtained by scraping, not hack CNET · Rae Hodge
- More than 500 million users' information leaked, Facebook: does not intend to inform relevant users equalocean.com
- Start Up No.1523: how Facebook's data leaked out, Spotify buys ‘Clubhouse for sports’, Apple helps others find your stuff, and more The Overspill · Charlesarthur
Discussion
-
@epro
Emil Protalinski
on x
Facebook did not comply with laws around the world that require disclosing such data leaks because it calculated that paying the fines, if and when they came, would cost less than the negative press resulting from notifying 533 million affected users. https://twitter.com/...
-
@tiffanycli
Tiffany C. Li
on x
I'm confused. Did all 50 state data breach notification laws suddenly stop existing, and also the FTC stopped existing, and the GDPR stopped existing too? Because that's the only scenario where this doesn't land Facebook in a heap of legal trouble. https://www.reuters.com/...
-
@jason_kint
Jason Kint
on x
We're up to a couple hundred people in this Twitter Space including the technologists who discovered the Facebook vulnerability, the 500 million personal data records, and others who have spent careers trying to get Facebook to be a better company. https://twitter.com/... https:/…
-
@jason_kint
Jason Kint
on x
This here says everything you need to know about the FTC and SEC walking away from dealing with the real problem in 2019. Now the question will be whether the $5 billion from the settlement has still has some juice to make this go away, too. https://twitter.com/...
-
@jason_kint
Jason Kint
on x
It included their phone numbers and according to reports it included non-public phone numbers used for lost passwords and two-factor authentication! But they're not going to tell anyone???!?!? https://twitter.com/...
-
@stickermule
@stickermule
on x
FACEBOOK is trying very hard to cover up their latest scandal and failing very badly!
-
@varunjuice
Varun Singh
on x
Zero surprise that the root cause for this traces back to the Growth team - the most cavalier perhaps of all teams at FB. https://twitter.com/...
-
@ashk4n
Ashkan Soltani
on x
Telling insights from a former @Facebook PM 👇 PPL I've talked to / cases I've worked on repeatedly point to the growth teams as the root cause of many of the past privacy disasters at @Google & @Facebook I've said before: “growth at any cost” is the new “unsafe at any speed” http…
-
@matthew_d_green
Matthew Green
on x
Remembering when Facebook started collecting phone numbers “for 2FA purposes” and how well that worked out. https://twitter.com/...
-
@tonyajoriley
Tonya Riley
on x
Facebook will NOT notify users if their data was included in a massive breach, Reuters reports. Seems like something that will come up when Congress finally has a hearing dedicated to data breaches https://www.reuters.com/... https://twitter.com/...
-
@astepanovich
Amie Stepanovich
on x
I've been saying for a long time — too long — that our data breach laws are too narrow and don't cover nearly enough information. Most (not all) are far too tied to financial info or gov identifiers. In the social media age we need to greatly expand our thinking. https://twitter.…
-
@carolecadwalla
Carole Cadwalladr
on x
‘Facebook is trying to frame this as a ‘scrape’ not a ‘hack’ but this is completely misleading. It revealed non-public information. It linked phone numbers to profiles. And that was private information’- @ashk4n
-
@matthew_d_green
Matthew Green
on x
I'm not going to say that Facebook's totally stupid treatment of that identifier set back customer security by a decade but maybe five years?
-
@jason_kint
Jason Kint
on x
A bit of an understatement, “This is not the first time Facebook's $80 billion advertising arm has potentially profited from hate or extremism.” Congrats marketers. https://twitter.com/...
-
@campuscodi
Catalin Cimpanu
on x
Good on them! The bigger the arrogance, the bigger the fine https://twitter.com/...
-
@grady_booch
Grady Booch
on x
Facebook is a profoundly unethical- and increasingly incompetent- organization, and it starts at the top, with Mark. https://www.reuters.com/...
-
@profcarroll
David Carroll
on x
Why the Facebook contact uploader vulnerability and subsequent hackbreachleak matters. Phone numbers are the ideal attack surface to force multiply other vulnerabilities. Facebook exposed non-public information and needs to answer for it. https://twitter.com/...
-
@slpng_giants
@slpng_giants
on x
This was phenomenal. @facebook may be good at obfuscation, but the sheer numbers of smart, knowledgeable people who are on to them is staggering. https://twitter.com/...
-
@intidc
Inti De Ceukelaire
on x
This was a historical call. Journalists from different agencies, regulators and tech experts exchanging info on the same story they're covering. Teaming up instead of allowing Facebook's toxic PR comms to divide them. https://twitter.com/...
-
@profcarroll
David Carroll
on x
Wow. @intdc explains how Facebook silently changing its confusing privacy settings set the stage for this catastrophic leak by making it too difficult to realize the difference between the visibility of your phone number vs. lookup by phone number. Cambridge Analytica déjà vu.
-
@jason_kint
Jason Kint
on x
ok, we're at point where Facebook seems focused on fragmenting info re: this data leak - it's hard to keep track of what's what - *a perfect case to light up Twitter Spaces.* I'm going to go live shortly @12pm ET - welcome anyone interested in listening, sharing notes, questions.…
-
@profcarroll
David Carroll
on x
Facebook revealed non-public information. Case closed. Don't let them spin this with gas lighting you on hack, breach, leak, nonsense.
-
@mikko
@mikko
on x
Facebook assures us that it's important that your phone number was not stolen from Facebook by hacking. It was stolen by scraping. https://twitter.com/...
-
@carolecadwalla
Carole Cadwalladr
on x
I've been tweeting about latest Facebook breach because it seems to show it's learned nothing since Cambridge Analytica. It's refused to answer basic press inquiries. And now, it's pulled out rest of Cambridge Analytica playbook. This isn't FB's fault. It's ‘malicious actors’ 1/ …
-
@mikko
@mikko
on x
How was Facebook scraped? Effectively, the attacker created an address book with every phone number on the planet and then asked Facebook if his ‘friends’ are on Facebook.
-
@ashk4n
Ashkan Soltani
on x
Facebook confirms that a sample of the 533M data is related to a ‘contact importers vulnerability’ which was fixed in Aug 2019 While there was some reporting of a ‘contact importer vuln’ in 2019, @Facebook never actually disclosed any details or notified affected users (1/6) http…
-
@carolecadwalla
Carole Cadwalladr
on x
It took Facebook 5 days to publish this. It's refusing to even acknowledge journalists's qs. It doesn't appear to be cooperating with the regulator. And these are not ‘facts’. This is a high-stakes PR op that blames Facebook's users for their shocking failure to protect them http…
-
@vmanancourt
Vincent Manancourt
on x
.@laurenscerulus and I were able to contact a European head of state and a top EU Commissioner *directly* using details in the Facebook leak. Imagine what sophisticated scammers could do. https://www.politico.eu/...
-
@ashk4n
Ashkan Soltani
on x
Also happening *now*. Someone (that I don't know) listening to the Spaces chat offered to demonstrate an SS7 exploit against my number to hijack my @PayPal account. (The attacker's phone number is fake) https://twitter.com/... https://twitter.com/...
-
@ashk4n
Ashkan Soltani
on x
Not only is @Facebook past the indemnification period of the FTC settlement (June 12 2019), they also may have violated the terms of the settlement requiring them to report breaches of covered information (ht @JustinBrookman ) https://www.ftc.gov/... https://twitter.com/...
-
@rmac18
@rmac18
on x
Just saw this explanation from Facebook about the data leak, which interestingly claims it's focused on protecting people because “scraping data” is against its terms of service. That's funny because FB has done nothing about Clearview AI scraping photos. https://t.co/K1vGX6icD6 …
-
@sarahfrier
Sarah Frier
on x
This is so reminiscent of the days following the Cambridge Analytica news, during which Facebook just kept saying it wasn't a hack, and didn't apologize. That strategy didn't work for them then... https://twitter.com/...
-
@mikko
@mikko
on x
For users who try to maintain an unlisted number, the distinction between hacking and scraping might not feel that important. Lots of politicians, celebrities and people with abusive ex-partners had their phone numbers exposed.
-
@caseynewton
Casey Newton
on x
Truly heroic amount of work from @lilyhnewman to untangle which leaked Facebook data is part of this recent breach, which seems to be at odds with the company's statements so far. https://t.co/iA9Tn7HsQm
-
@abiaad
Pierre Abi-aad
on x
My #Facebook account is closed and removed since 2015 but my phone number is part a data breach fixed in 2019. This is fucking scary. #privacy #breach https://twitter.com/...
-
@fboversight
@fboversight
on x
Journalists from @Politico managed to contact a EU commissioner and a head of state via the Facebook data breach. “Imagine what sophisticated scammers could do” to any of the users involved in the leak. https://twitter.com/...
-
@daithaigilbert
David Gilbert
on x
Facebook has addressed the leak of a database containing the phone numbers of 533 Million users. It's repsonse? It's not our fault, it's yours https://www.vice.com/...