Malaysia

Data of Facebook users, including 11 million M’sians, skimmed off contact feature: developer

Social media giant says no internal system hacking involved; malicious actors collected information using automated software

Updated 3 years ago · Published on 08 Apr 2021 9:00AM

Data of Facebook users, including 11 million M’sians, skimmed off contact feature: developer
Facebook says the specific issue that allowed certain parties to lift user data in 2019 has been fixed, but the damage has been done and the misdeed has resulted in the particulars of some 530 million users being leaked on an online hacker’s forum recently. – AFP pic, April 8, 2021

by A. Azim Idris

KUALA LUMPUR – Social media giant Facebook insists that the leak of personal data of 530 million users – including 11 million Malaysians – to hackers recently was “scraped” from one of its open contact features, and not hacked from its internal systems.

In a blog post on its corporate website, Facebook product management director Mike Clark said malicious actors had obtained the data using a common “scraping” tactic that relies on automated software to lift public information from the internet.

He explained that the data can end up being distributed in online forums, adding that the methods used to obtain the data set were previously reported in 2019.

Clark said Facebook believes the data involved was scraped from people’s Facebook profiles using the platform’s contact importer feature prior to September 2019.

The feature, he said, was designed to help people easily find their friends to connect with on the service using their contact lists.

After Facebook became aware of how malicious actors were using this feature in 2019, the developers made changes to the contact importer, Clark said.

“In this case, we updated it to prevent malicious actors from using software to imitate our app and upload a large set of phone numbers to see which ones matched Facebook users,” he said.

“Through the previous functionality, they were able to query a set of user profiles and obtain a limited set of information about those users included in their public profiles. The information did not include financial information, health information, or passwords.

“This is another example of the ongoing, adversarial relationship technology companies have with fraudsters who intentionally break platform policies to scrape internet services,” Clark said.

“As a result of the action we took, we are confident that the specific issue that allowed them to scrape this data in 2019 no longer exists.”

Over 11 million Malaysians affected

On Monday, local technology portal Lowyat.net reported that over 11 million Malaysian Facebook users are purportedly part of the more than 500 million accounts’ information leaked on an online hackers’ forum recently.

The massive data leak was first reported by Business Insider on April 3, which said the exposed data includes the personal information of over 533 million Facebook users from 106 countries.

This included more than 32 million records on users in the US, 11 million on users in the UK, and 6 million on users in India, Business Insider reported.

The number of local users, totalling 11,675,894, was revealed by Alon Gal, who is the co-founder and chief technology officer of Israeli cybersecurity company Hudson Rock.

Gal gave a breakdown of affected accounts according to countries in a tweet on January 14, which was retweeted on April 3.

Other than Facebook IDs, Gal pointed out that users’ phone numbers, full names, locations, past locations, birthdays, relationship statuses, bios, and email addresses are also among details leaked. – The Vibes, April 8, 2021

Related News

Malaysia / 2mth

Man seeks original owner of RM50 with message ‘Last money from dad’

Malaysia / 3mth

MoF: Nurul Izzah is not a paid Laksana advisor

Malaysia / 3mth

Najib’s team slam Ramkarpal, others for not grasping facts of his case, invite televised debate

Malaysia / 3mth

Singaporean alleges Malaysian workshop owner called him ‘l*nsi’

Malaysia / 5mth

Fahmi denies govt removing social media content amid criticism

Culture & Lifestyle / 5mth

Johor boy Ronny Chieng elated to host The Daily Show

Spotlight

Malaysia

PRS proposes party president to fill vacant Senate president’s post

Malaysia

Ex-inspector escapes gallows, gets 33 years for wife’s murder

Malaysia

Foreigners make up 10% of Malaysia population

Malaysia

Cop pleads not guilty to student’s murder

Malaysia

Banks warn about scammers who impersonate NSRC officers

Malaysia

Jeffrey recalls memories of ISA confinement 33 years later

By Jason Santos

You may be interested

Malaysia

UiTM Bumiputera-only admission policy stays

Malaysia

SLS appeal hearing draws strong police presence

Malaysia

Political shifts, persistent poverty of Kota Marudu

By Jason Santos

Malaysia

Court postpones decision on 40% judicial review

By Jason Santos

Malaysia

Kayak athlete badly injured after crash with alleged drunk driver

Malaysia

Assistant supervisor pleads not guilty to drunk driving, injuring national kayak athlete

Malaysia

Sarawak to charge 5% forest carbon trading fee

By Desmond Davidson

Malaysia

PRS proposes party president to fill vacant Senate president’s post