Facebook hack : the fallout

The after effects of the Facebook hack and how it may affect you

Ned Poplaski (CISSP)
2 min readApr 19, 2021
The webpage from Digital Rights Ireland (DRI)

Background

Data from 533 million accounts was leaked from Facebook ( even that of CEO Mark Zuckerberg’s ). Here are some details on what we know now and about the kind of data that was compromised.

What was the exploit ?

Using the loopholes in Facebook’s contact importer feature. Remember the feature ? It allows anyone to find friends on social media using their phone’s contact list.

What kind of data was compromised ?

  • Facebook ID numbers
  • profile names
  • email addresses
  • location information
  • gender details
  • job data and certain other details.

Who will possibly benefit from this ?

This is a rich source of user profile for those who employ phishing as a means to gain access to any vital information of the victim. This is also a treasure trove of information for focused scammers.

Will Facebook notify those affected ?

No.

Aftermath

  • Soon after the reveal, Facebook has notified that it has ‘made changes to the contact importer feature’ and now it is not possible for the old data to be scraped from the site.
  • On April 16th [1] , Digital Rights Ireland (DRI ) has filed a mass action lawsuit against the company under provisions in the EU GDPR , article 82. ( right to compensation and liability )

Links

[1] Facebook faces ‘mass action’ lawsuit in Europe over 2019 breach

Digital Rights Ireland suing Facebook

--

--

Ned Poplaski (CISSP)

I share news and Lessons to make possible a safer cyber experience. cyber security educator. ex-McAfee, Consultant snyk.io,sonatype.