{"id":65038,"date":"2021-04-07T16:16:00","date_gmt":"2021-04-07T23:16:00","guid":{"rendered":"https:\/\/blog.mozilla.org\/foxtail\/?p=65038"},"modified":"2021-08-06T14:36:59","modified_gmt":"2021-08-06T21:36:59","slug":"facebook-data-leak-explained","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/","title":{"rendered":"You\u2019ve been scraped, the Facebook data leak explained"},"content":{"rendered":"\n<p>In early April, <a href=\"https:\/\/www.businessinsider.com\/stolen-data-of-533-million-facebook-users-leaked-online-2021-4\">it was reported<\/a> that there had been a Facebook data leak, raising alarms among Facebook account holders. Half a billion Facebook accounts were impacted. The dataset is from 2019, so it had been out there, but not widely circulated. Over the weekend, the data started popping up on popular hacking forums for free. The interesting story is where the data likely came from, what can be done with it, and what you can do to protect yourself.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"960\" height=\"242\" src=\"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/hibp-facebook-alert.png\" alt=\"\" class=\"wp-image-65039\" srcset=\"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/hibp-facebook-alert.png 960w, https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/hibp-facebook-alert-300x76.png 300w, https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/hibp-facebook-alert-768x194.png 768w\" sizes=\"(max-width: 960px) 100vw, 960px\" \/><figcaption><em>Alert from <\/em><a href=\"https:\/\/haveibeenpwned.com\/\"><em>haveibeenpwned<\/em><\/a><em>.<\/em><\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><b>What was in the April 2021 Facebook data leak?<\/b><\/h2>\n\n\n\n<p>Data for more than <a href=\"https:\/\/about.fb.com\/news\/2021\/04\/facts-on-news-reports-about-facebook-data\/\">500 million Facebook accounts<\/a> was included in this data dump. It appears that most records included Facebook ID numbers, names, gender and phone numbers. Some records also included birth dates, location, relationship status and employer.<\/p>\n\n\n\n<p>Most of this data does not seem to have been acquired through typical data breach methods, meaning it wasn\u2019t collected by breaking into Facebook\u2019s databases. Instead, it was \u201cscraped\u201d from information that users themselves made visible.<\/p>\n\n\n\n<p>Attackers scraped Facebook data by exploiting a vulnerability in Facebook&#8217;s Contact Importer feature in 2019. From what has been <a href=\"https:\/\/www.axios.com\/facebook-data-533-million-leak-bda53583-363a-4e4a-bc38-b147c3e12a8c.html\">reported<\/a>, the individuals probably used <a href=\"https:\/\/developer.android.com\/studio\/run\/emulator\">Android emulators<\/a>, which is software that simulates an Android device on a computer. They loaded, say, 10k phone numbers into the address book of the emulated device, installed Facebook&#8217;s mobile app, and used the app\u2019s &#8220;import contacts&#8221; feature to get the rest of the profile data for those 10k phone numbers. Then they wiped the device and did the same thing with another batch of 10k phone numbers, etc. etc.<\/p>\n\n\n\n<p>A combination of privacy settings led to data vulnerability:<\/p>\n\n\n\n<ul><li aria-level=\"1\">Profile data being set to \u201cPublic\u201d or share with \u201cFriends&#8221;<\/li><li aria-level=\"1\">In Facebook privacy settings, people had &#8220;who can look you up using the phone number you provided&#8221; set to &#8220;Everyone&#8221;<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><b>Recommended security steps<\/b><\/h2>\n\n\n\n<p>Even if your Facebook login, email or password information isn&#8217;t in this dataset, your phone number may still be vulnerable. You can check to see if your phone number was in the leak at <a href=\"https:\/\/haveibeenpwned.com\/\">haveibeenpwned.com<\/a>.<\/p>\n\n\n\n<p>If you have ever signed up for a Facebook account \u2014 even if you don\u2019t use it now \u2014 we recommend you take these steps to protect yourself:<\/p>\n\n\n\n<p><b>1. Change your profile information to private in your<\/b><b> Facebook privacy settings. <\/b><\/p>\n\n\n\n<p>During this breach, hackers took profile information that was set as open to \u201cPublic\u201d or shared with \u201cFriends.\u201d This information can be matched and combined with data from other breaches to access even more of your personal information and accounts.<\/p>\n\n\n\n<p>Visit <a href=\"https:\/\/www.facebook.com\/me\/about\">https:\/\/www.facebook.com\/me\/about<\/a>. Go through all of the sections in your Facebook profile on the left, and consider setting them to Private or Friends on the right. The less you make public, the more private and secure you will likely be.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"880\" height=\"380\" src=\"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/facebook-about-privacy.png\" alt=\"\" class=\"wp-image-65049\" srcset=\"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/facebook-about-privacy.png 880w, https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/facebook-about-privacy-300x130.png 300w, https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/facebook-about-privacy-768x332.png 768w\" sizes=\"(max-width: 880px) 100vw, 880px\" \/><\/figure><\/div>\n\n\n\n<p><b>2. Adjust who can find and contact you on Facebook.<\/b> Visit your <a href=\"https:\/\/www.facebook.com\/settings?tab=privacy\">Facebook Privacy settings<\/a> and set them all to Friends or more strict for stronger security.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img decoding=\"async\" loading=\"lazy\" width=\"884\" height=\"292\" src=\"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/facebook-account-privacy-contact.png\" alt=\"\" class=\"wp-image-65059\" srcset=\"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/facebook-account-privacy-contact.png 884w, https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/facebook-account-privacy-contact-300x99.png 300w, https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/facebook-account-privacy-contact-768x254.png 768w\" sizes=\"(max-width: 884px) 100vw, 884px\" \/><\/figure><\/div>\n\n\n\n<p><b>3. Change the passcode or PIN on your mobile phone carrier accounts to prevent SIM swapping. <\/b>SIM swapping is when a criminal uses phone numbers, date of birth and other data to take over a person\u2019s cell phone number and then hack into their email, social media and even financial accounts. <a href=\"https:\/\/blog.mozilla.org\/en\/internet-culture\/mozilla-explains\/mozilla-explains-sim-swapping\/\">Learn more about how SIM swapping works.<\/a><\/p>\n\n\n\n<p><b>4. Review all of your Facebook privacy settings.<\/b> As the Facebook platform evolves and grows, parts of your account could be public in surprising ways. Data could also be collected and shared in ways you don\u2019t know about. <b><\/b><\/p>\n\n\n\n<p><b>5. Sign up for <\/b><a href=\"https:\/\/monitor.firefox.com\/?utm_source=blog.mozilla.org&amp;utm_campaign=firefox_frontier&amp;utm_medium=referral&amp;utm_content=mozilla-explains\"><b>Firefox Monito<\/b>r<\/a> to see if your email address has been part of a previous data breach and get alerted to future ones.<\/p>\n\n\n\n<p>The bottom line is you don\u2019t need to wait for a data breach to get smart about your security. Being alert to issues like data breaches and SIM swapping is part of modern internet citizenship as we do more with our devices and live online.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In early April, it was reported that there had been a Facebook data leak, raising alarms among Facebook account holders. Half a billion Facebook accounts were impacted. The dataset is from 2019, so it had been out there, but not widely circulated. Over the weekend, the data started popping up on popular hacking forums for [&hellip;]<\/p>\n","protected":false},"author":727,"featured_media":65069,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[464058,461998,289374],"tags":[],"coauthors":[311664],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>You\u2019ve been scraped, the Facebook data leak explained<\/title>\n<meta name=\"description\" content=\"Even if your login, email or password aren&#039;t in the Facebook data leak, your phone number may still be vulnerable. Take these steps to protect yourself.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/\",\"url\":\"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/\",\"name\":\"You\u2019ve been scraped, the Facebook data leak explained\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/fx_blog_header_emergince_tech_innovation_001_1920x1080.jpg\",\"datePublished\":\"2021-04-07T23:16:00+00:00\",\"dateModified\":\"2021-08-06T21:36:59+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/5c987afc4f606be73692d2acfdd1316c\"},\"description\":\"Even if your login, email or password aren't in the Facebook data leak, your phone number may still be vulnerable. Take these steps to protect yourself.\",\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/#primaryimage\",\"url\":\"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/fx_blog_header_emergince_tech_innovation_001_1920x1080.jpg\",\"contentUrl\":\"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/fx_blog_header_emergince_tech_innovation_001_1920x1080.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"Stylized illustration of colorful code lines in red, orange, and white on a purple background, representing programming and software development.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"You\u2019ve been scraped, the Facebook data leak explained\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/en\/\",\"name\":\"The Mozilla Blog\",\"description\":\"News and Updates about Mozilla\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/en\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/5c987afc4f606be73692d2acfdd1316c\",\"name\":\"M.J. Kelly\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/image\/70718b02fa9f11d88288b937f1da2ac1\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d61ff6a9eb6dd324df20cb773e6c416e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d61ff6a9eb6dd324df20cb773e6c416e?s=96&d=mm&r=g\",\"caption\":\"M.J. Kelly\"},\"description\":\"Mozilla Communications\",\"url\":\"https:\/\/blog.mozilla.org\/en\/author\/mjkellymozilla-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"You\u2019ve been scraped, the Facebook data leak explained","description":"Even if your login, email or password aren't in the Facebook data leak, your phone number may still be vulnerable. Take these steps to protect yourself.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/","url":"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/","name":"You\u2019ve been scraped, the Facebook data leak explained","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/#primaryimage"},"image":{"@id":"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/fx_blog_header_emergince_tech_innovation_001_1920x1080.jpg","datePublished":"2021-04-07T23:16:00+00:00","dateModified":"2021-08-06T21:36:59+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/5c987afc4f606be73692d2acfdd1316c"},"description":"Even if your login, email or password aren't in the Facebook data leak, your phone number may still be vulnerable. Take these steps to protect yourself.","breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/#primaryimage","url":"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/fx_blog_header_emergince_tech_innovation_001_1920x1080.jpg","contentUrl":"https:\/\/blog.mozilla.org\/wp-content\/blogs.dir\/278\/files\/2021\/05\/fx_blog_header_emergince_tech_innovation_001_1920x1080.jpg","width":1920,"height":1080,"caption":"Stylized illustration of colorful code lines in red, orange, and white on a purple background, representing programming and software development."},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/en\/privacy-security\/facebook-data-leak-explained\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/en\/"},{"@type":"ListItem","position":2,"name":"You\u2019ve been scraped, the Facebook data leak explained"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/en\/#website","url":"https:\/\/blog.mozilla.org\/en\/","name":"The Mozilla Blog","description":"News and Updates about Mozilla","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/en\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/5c987afc4f606be73692d2acfdd1316c","name":"M.J. Kelly","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/en\/#\/schema\/person\/image\/70718b02fa9f11d88288b937f1da2ac1","url":"https:\/\/secure.gravatar.com\/avatar\/d61ff6a9eb6dd324df20cb773e6c416e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d61ff6a9eb6dd324df20cb773e6c416e?s=96&d=mm&r=g","caption":"M.J. Kelly"},"description":"Mozilla Communications","url":"https:\/\/blog.mozilla.org\/en\/author\/mjkellymozilla-com\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/posts\/65038"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/users\/727"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/comments?post=65038"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/posts\/65038\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/media\/65069"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/media?parent=65038"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/categories?post=65038"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/tags?post=65038"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/en\/wp-json\/wp\/v2\/coauthors?post=65038"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}