Millions of Facebook users have data exposed online

Facebook
(Image credit: Shutterstock)

Two huge databases containing the records of over 300 million Facebook users, including their user IDs, phone numbers and names, have been leaked online.

The breach was detected by security researcher Bob Diachenko, who found the first exposed database last December. 

He believes that the large collection of Facebook user data was collected by cybercriminals in Vietnam either through an illegal scraping operation or by abusing the social network's API based on the evidence he uncovered.

In situations such as this, Diachenko usually notifies database owners first but since this data likely belonged to a criminal organization, he notified the internet service provider managing the IP address of the exposed server instead. Unfortunately, the leaked data was also posted on a hacker forum where others can download it and use it to launch phishing and other cyberattacks online.

Now, a second server containing the same data along with an additional 42m records has also been discovered, apparently operated by the same group of cybercriminals. However, shortly after the second server was found, it was attacked by an unknown party and the information it stored was replaced with dummy data and database names which read “please_secure_your_servers”.

Exposed data

The first exposed database contained 267m records and most of the affected users were from the US. Each record contained a unique Facebook ID, a phone number, a full name and a timestamp.

The second exposed server contained the same 267m records plus an additional 42m records and was hosted on a US Elasticsearch server. 25M of the records it contained had similar information as that contained in the first server but 16.8m of the new records contained additional information including users' profile details, email addresses and other personal details.

While it is still unclear at this time whether the data was obtained through the Facebook API or through a process called scraping where automated bots copy data from websites, Comparitech (who partnered with Diachenko on this discovery) does have some recommendations on how you can avoid having your data scraped.

To minimize the chances of having your profile scraped by strangers, the firm recommends that users go to their Facebook settings, click on “Privacy” and set all relevant fields from “Friends” to “Only Me”. Additionally, users should set the “Do you want search engines outside of Facebook to link to your profile” option to “No” to reduce the chances of having their profiles scraped by third parties.

  • Also check out our complete list of the best VPN services

Via Comparitech

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Software & Services
Windows 11 Start menu layout choices: Grid view
Windows 11 vs Linux for business: which operating system should you embrace?
A phone sitting on a laptop keyboard with the Microsoft Outlook logo on the screen.
Gmail vs Outlook for business: which email system is right for your organization?
Windows 11 logo
Windows 11 Pro vs Windows 11 Home: which version is right for you?
Canva HubSpot
HubSpot and Canva team up to level the creative playing field
a laptop computer
Windows 11 vs ChromeOS for business: Is one better than the other for your needs?
a laptop computer
Windows 11 vs macOS for business: which side are you on?
Latest in News
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
An Nvidia GeForce RTX 4060 on a table with its retail packaging
Nvidia RTX 5060 GPU spotted in Acer gaming PC, suggesting rumors of imminent launch are correct – and that it’ll run with only 8GB of video RAM
Indiana Jones talking to a friend in a university setting with a jaunty smile on his face
New leak claims Indiana Jones and the Great Circle PS5 release will come in April
A close up of the limited edition vinyl turntable wrist watch from AndoAndoAndo
This limited-edition timepiece turns the iconic Technics SL-1200 turntable into a watch, and I want one
A close up of Gemma sitting down in Severance season 2 episode 7
'I'm like Gemma – I'm in the dark': Severance star Dichen Lachman shares disappointing filming update for the popular Apple TV+ show's third season
Horizon Zero Dawn Remastered
Future PlayStation games could have AI-powered characters, if this leaked prototype of Aloy is anything to go by