Indian-origin researcher finds 419mn Facebook users' exposed data


San Francisco, Sep 5 (IANS): Sanyam Jain, a security researcher and member at Hague-based non-profit organisation GDI Foundation, has discovered a massive database containing over 419 million phone numbers of Facebook users on an unsecured server which were available for anyone to access.

The database included 133 million records of US-based Facebook users, 18 million records of UK users and more than 50 million records of users in Vietnam, TechCrunch reported on Wednesday.

According to Jain, he found profiles with phone numbers associated with several celebrities.

"Jain... found the database and contacted TechCrunch after he was unable to find the owner. After a review of the data, neither could we. But after we contacted the web host, the database was pulled offline," said the report.

This latest data breach exposed millions of users' phone numbers just from their Facebook IDs, putting them at risk of spam calls and 'SIM-swapping' or 'SIM jacking' where a mobile number is transferred to a new SIM card.

"This dataset is old and appears to have information obtained before we made changes last year to remove people's ability to find others using their phone numbers," a Facebook spokesperson was quoted as saying by the Engadget.

After the web host was contacted, the Facebook users' database was pulled offline.

Some of the records also had the user's name, gender and location by country.

There have been several incidents after the Cambridge Analytica episode involving 87 million users where Facebook acknowledged series of privacy lapses, including the latest admission that it mishandled millions of users' passwords on Instagram and "unintentionally" uploaded emails of nearly 1.5 million of its new users.

  

Top Stories


Leave a Comment

Title: Indian-origin researcher finds 419mn Facebook users' exposed data



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.