Report: 267 million Facebook users IDs and phone numbers exposed online

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
A database containing more than 267 million Facebook user IDs, phone numbers, and names was left exposed on the web for anyone to access without a password or any other authentication.

Comparitech partnered with security researcher Bob Diachenko to uncover the Elasticsearch cluster. Diachenko believes the trove of data is most likely the result of an illegal scraping operation or Facebook API abuse by criminals in Vietnam, according to the evidence.

The information contained in the database could be used to conduct large-scale SMS spam and phishing campaigns, among other threats to end users.
Diachenko immediately notified the internet service provider managing the IP address of the server so that access could be removed. However, Diachenko says the data was also posted to a hacker forum as a download.

Timeline of the exposure
The database was exposed for nearly two weeks before access was removed. Here’s what we know:

  • December 4 – The database was first indexed.
  • December 12 – The data was posted as a download on a hacker forum.
  • December 14 – Diachenko discovered the database and immediately sent an abuse report to the ISP managing the IP address of the server.
  • December 19 – The database is now unavailable.
... ... ...
 

SecretKeeper

Level 3
Verified
Well-known
Dec 25, 2015
120
This doesn't surprise me anymore; I had an account to stay in touch with family, even though I deleted my last account after the Analytica scandal. As soon as I heard this on the news, I just deleted it again without hesitation. It will be my last account for sure.

I hope one day they get shut down.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top