Source:
https://scmp.com/news/world/united-states-canada/article/3025779/419-million-exposed-your-phone-number-affected
World/ United States & Canada

419 million exposed: is your phone number affected by Facebook’s latest security bungle?

  • The information was stored in an online server that was not password protected, according to a report from TechCrunch
The information was stored in an online server that was not password protected, according to a report from TechCrunch. Photo: AP

Hundreds of millions of Facebook users’ phone numbers were exposed in an open online database, the company confirmed, in the latest example of Facebook’s past privacy lapses coming back to haunt its users.

More than 419 million Facebook IDs and phone numbers were stored in an online server that was not password protected, the technology website TechCrunch reported.

The data set included about 133 million records for users in the US, 18 million records for users in the UK and 50 million records for users in Vietnam.

The database was taken offline after TechCrunch contacted the web host.

Facebook confirmed the report and said it was investigating when and by whom the database was compiled.

A spokeswoman for the company also claimed that the actual number of users whose information was exposed was around 210 million, because the 419 million records contained duplicates.

The records were likely amassed using a tool that Facebook disabled in April 2018 in the aftermath of the Cambridge Analytica controversy.

The revelations showed how Facebook’s lax approach to privacy had allowed a political consultancy to obtain personal information from tens of millions of profiles.

Until then, Facebook allowed anyone to search for users by their phone number, a seemingly benign tool for finding an individual with a common name that was also readily hijacked by data scrapers.

“Malicious actors have also abused these features to scrape public profile information by submitting phone numbers or email addresses they already have through search,” chief technology officer Mike Schroepfer wrote at the time.

“Given the scale and sophistication of the activity we’ve seen, we believe most people on Facebook could have had their public profile scraped in this way.”

Facebook emphasised that the exposed data was “old” and would have been scraped prior to the April 2018 policy change.

“This data set is old and appears to have information obtained before we made changes last year to remove people’s ability to find others using their phone numbers,” a spokeswoman said in a statement.

“The data set has been taken down and we have seen no evidence that Facebook accounts were compromised.”

The spokeswoman did not respond to questions about whether Facebook would tell users whose information was exposed or offer any mitigation to those affected, saying only that the company was still investigating.

Facebook’s characterisation of the data as “old” notwithstanding, phone numbers are an increasingly important key to people’s identities – and a potential vulnerability.

While not as sensitive as a social security number, they are important identifiers that can be used to easily obtain significant amounts of personal information about an individual and their family from online data brokers, as The New York Times reported in August.

Skilled attackers can often leverage a mobile phone number and information gained through data brokers or social media sites (such as home address, previous addresses, family members, etc) to persuade mobile phone carriers to transfer a target’s phone number to a different phone.

The latest high-profile victim of this type of attack, which is known as Sim swapping, was Twitter chief executive officer Jack Dorsey, whose Twitter account was hijacked on Friday by a hacking group that appears to have gained control of his mobile phone number.

On Wednesday, Twitter announced that it was temporarily disabling the ability for users to send tweets through SMS, or text messages, due to “vulnerabilities that need to be addressed by mobile carriers”.

For more insights into China tech, join our Facebook group, subscribe to our Inside China Tech podcast, and download the comprehensive 2019 China Internet Report. Also roam China Tech City, an award-winning interactive digital map at our sister site Abacus.