Facebook confirms 419m phone numbers exposed in latest privacy lapse
Hundreds of millions of Facebook users’ phone numbers were exposed in an open online database, the company confirmed Wednesday, in the latest example of Facebook’s past privacy lapses coming back to haunt its users.
More than 419m Facebook IDs and phone numbers were stored in an online server that was not password protected, The Guardian reported, citing the technology website TechCrunch.
The dataset included about 133m records for users in the US, 18m records for users in the UK and 50m records for users in Vietnam.
The database was taken offline after TechCrunch contacted the web host.
Facebook confirmed the report and said it was investigating when and by whom the database was compiled. A spokeswoman for the company also claimed that the actual number of users whose information was exposed was approximately 210m, because the 419m records contained duplicates.
The records were likely amassed using a tool that Facebook disabled in April 2018 in the aftermath of the Cambridge Analytica controversy. The revelations showed how Facebook’s lax approach to privacy had allowed a political consultancy to obtain personal information from tens of millions of profiles.
Until then, Facebook allowed anyone to search for users by their phone number, a seemingly benign tool for finding an individual with a common name that was also readily hijacked by data scrapers.
Facebook emphasized that the exposed data was “old” and would have been scraped prior to the April 2018 policy change.
“This dataset is old and appears to have information obtained before we made changes last year to remove people’s ability to find others using their phone numbers,” a spokeswoman said in a statement. “The dataset has been taken down and we have seen no evidence that Facebook accounts were compromised.”
The spokeswoman did not respond to questions about whether Facebook would inform users whose information was exposed or offer any mitigation to those affected, saying only that the company was still investigating.