Facebook knew about the massive data breach since 2019 but didn't warn anyone 1

Facebook knew about the massive data breach since 2019 but didn’t warn anyone

Facebook

This weekend, a hacker released the personal data of 533 million Facebook users, 20 million of whom were French. one of the most important leaks in the history of social networksBut this is not his first attempt. Among the published information we find: profile names, phone numbers and even email addressesMark Zuckerberg’s group spoke about the issue on April 6, in the person of product management director Mike Clark.

Second, the defect that caused the leak Known by Facebook since 2019. It was quickly sealed in August of that year. But as Mike Clark admitted, there remains a problem The breach in question was not the subject of any statementUnlike the other two similar cases that occurred in the following months. As a reminder, we learned that in September 419 million phone numbers were released. In December, this time, 267 million users were leaked.

Facebook did not mention the flaw that caused the data leak

Mike Clark explains what hackers are using A flaw in the contact import functionality. While it was quickly detected and fixed, it’s not possible to know how many times it was used. Until now, communication about the incident has been limited to a brief comment in a Forbes article published in September 2019. At the time, a cybersecurity researcher discovered a vulnerability in Instagram’s address book. Here’s what Facebook responded to “Being already aware of the problem through an internal discovery”, Before making sure the problem is solved.

But it seems that the Forbes article in question concerning a defect entirely different from the lastAlthough the two are relatively similar. Therefore, Facebook did not warn either the authorities or the users that their data was potentially stolen. The Irish Data Protection Commission confirms this as follows: “I have not received any proactive communication from Facebook” in this respect.

“Previous databases were released in 2019 and 2018 following a large-scale attack on Facebook’s website that Facebook said occurred between June 2017 and April 2018, and while the social network was patching a flaw in its phone number search function.», explains the Commission. “Given that the attack took place before the GDPR [applicable depuis 2018, ndlr], Facebook chose not to report this as a personal data breach under the GDPR. The recently released database appears to contain all the original information from 2018 (pre-GDPR) and will likely be combined with other data collected later. »

Facebook is dangerously self-righteous

Mark Zuckerberg’s group, which was affected by the leak, also announced that it did not see fit to report the flaw because, according to him: There are already many user databases on the internet. Also, to exploit the vulnerability, it was necessary to find the victim’s phone number and associate a name with it. Nothing else is needed to verify this for FacebookHe is not responsible for the leaking of phone numbers.Mike Clark explains it this way: “It is important to understand that the attackers obtained this data not by hacking our systems, but by harvesting it from our platform prior to September 2019.”

So there is a distinction to be made between a legitimate but not very prudent functionality and a real flaw in the data system. It remains to be decided whether this major leak is the result of one or the other. But, For the victims the difference doesn’t really matterin both cases, those who saw their personal information exposed in broad daylight. The hackers’ observation is similar: The nature of the tool does not matter because it enables the collection of data. Moreover, it made it possible the link between phone numbers and the identity of the ownerThis likely led to other privacy breaches.

“It is a mistake to think that a breach is not a big deal just because it does not involve passwords or other highly sensitive data.”That’s according to the estimate of Zack Allen, director of threat intelligence at ZeroFox, a company specializing in cybersecurity. “It’s also wrong to say that a situation isn’t that serious because it’s old data. Additionally, phone numbers are often used as a form of authentication these days, and that can be very scary.[au vu de la situation]» .

Facebook claims it’s fighting to repair the damage caused by the flaw, or “weakness,” depending on your perspective. “We are focused on protecting our users’ data by working on a solution to delete it [des sites sur lesquelles elles sont hébergées] “We will continue to act aggressively against malicious individuals who use our vehicles for the wrong reasons.”Mike Clark writes. “While we can’t always prevent this database from circulating or new ones from emerging, we have a team dedicated to this task.”

Source : Wired

Support our work ❤️

If you enjoyed this article, consider leaving a tip to help us keep publishing great content.

Secure payment on PayPal
Moyens I/O Staff is a team of expert writers passionate about technology, innovation, and digital trends. With strong expertise in AI, mobile apps, gaming, and digital culture, we produce accurate, verified, and valuable content. Our mission: to provide reliable and clear information to help you navigate the ever-evolving digital world. Discover what our readers say on Trustpilot.