Tech
Risk of Massive Facebook Leak: 1.2 Billion Users May Be Affected by Cyberattack
Data from millions of accounts potentially accessible online—a new security scandal looms.
An unprecedented amount of Facebook user data has been posted on a popular hacker forum.
Attackers claim to have scraped information from as many as 1.2 billion users through a vulnerability in one of Facebook’s APIs. If the claim is verified, it would denote one of the largest data leaks in the tech giant’s history.
An Enormous Leak—But Yet to Be Confirmed
The cybersecurity-focused media outlet Cybernews has reported on the discovery.
Their research team analyzed a subset of the database, consisting of 100,000 unique Facebook user profiles.
Though the full scope is still unknown, the dataset appears authentic based on the preliminary sample.
The database allegedly contains:
- Usernames and full names
- Email addresses
- Phone numbers
- User IDs
- Locations, genders, and birthdates
This stirs concern among researchers, who emphasize that the entire leak has yet to be fully verified: “The attackers might have started with a smaller set and then expanded to 1.2 billion records. We do not know yet,” according to Cybernews.
Read also:
A Pattern of Reactive Security Strategies
If the leak is confirmed, it merely adds another chapter to Facebook’s long history of data security issues.
Critics point to Meta again appearing as an entity that responds too late to serious vulnerabilities.
Potential Consequences: Phishing, Fraud, and Identity Theft
If the datasets fall into the wrong hands, it could have severe consequences for users.
Cybercriminals could specifically target phishing attacks and scams at individuals who are confirmed Facebook users—a scenario that drastically reduces the need for random mass mailings and increases precision.
Facebook has faced similar issues before. In 2021, information about over 500 million users was leaked, resulting in a €265 million fine from the EU’s data protection authority.
Yet again, it appears the company’s handling of API accesses poses a critical security vulnerability.
Our team may have used AI to assist in the creation of this content, which has been reviewed by our editors.
Read also: