An unsecured database exposes more than 267 million Facebook User IDs, phone numbers, full name, and timestamp. The database exposed to the web without any authentication, by having the web URL anyone can access the database.
Security researcher Bob Diachenko partnered with Comparitech uncovered the Elasticsearch database, the database found to be open for nearly two weeks.
Diachenko believes that the data was scrapped illegally by abusing the Facebook API by Cybercriminals in Vietnam and they can be used to conduct mass spam and phishing campaigns.
The database found to be indexed on December 4th, the bad news is that Facebook user’s data are posted in the hacker forum on December 12th. The detailed posted on hacker forums could reach several cybercriminals, by having the data they can launch sophisticated attacks.
Diachenko uncovered the data on December 14th, and it was reported to the ISP, finally, the database was taken down on December 19th.
According to Diachenko, Facebook’s API could have a security hole that allows the cybercriminals to scrap the details, the exposed details include;
“In total 267,140,436 Facebook users records were exposed. Most of the affected users were from the United States. The server included a landing page with a login dashboard and welcome note,” Diachenko says.
Facebook restricted the data in 2018, before that details such as check-ins, likes, photos, posts, videos, events, and groups, possibly the data scrapped before that.
Also Read
U.S. Based Hospital to Pay $2.175M for Not Reporting the Data Breach of Health Care Data
Over 750,000 U.S Birth Certificate Applications Exposed Online From Unsecured AWS bucket
You can follow us on Linkedin, Twitter, Facebook for daily Cyber Security and hacking news updates.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…