Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



   991

Major Facebook data leak reveals 1.2 billion user records, hacker claims

by HIGHTORQUE - 22 May, 2025 - 03:46 AM
This post is by a banned member (HIGHTORQUE) - Unhide
504
Posts
333
Threads
2 Years of service
#1
A massive 1.2 billion user record database was scraped from the Meta-owned Facebook by abusing one of the social media platform‘s application programming interfaces (APIs), attackers claim.

The humongous database was posted on a popular data leak forum, with attackers claiming that the information is not a compilation of old records, but an entirely new dataset. If confirmed, the scrape could be one of the largest to come from Facebook.

We have reached out to Meta for comment and will update the article once we receive a reply.

The Cybernews research team investigated a data sample with records on 100,000 unique Facebook user records that attackers included in the post. Based on what‘s in the sample, not the complete dataset, the data appears legitimate.


[Image: facebook-data-leak-posts.jpg]

According to the team, the dataset includes:

    User IDs
    Names
    Email addresses
    Usernames
    Phone numbers
    Locations
    Birthdays
    Genders

While the attackers‘ claims are outstanding, researchers advise being cautious about the validity of the “1.2 billion Facebook user records” claims. For one, the post with supposed records scraped from Facebook is only the second that the attackers ever posted.


“Another attacker’s post also included data supposedly scraped from Facebook, but the batch was much smaller. It could be that they posted one post and then managed to scrape more info to reach 1.2B of records,” researchers said.


If confirmed, the Facebook data scrape would mean the social media platform would mark another instance where user data gets scraped en masse. The team believes this raises some questions about the company’s attitude towards users’ personal data security.


“Repeated incidents show a pattern of reactive rather than proactive security measures, particularly when it comes to protecting data that’s publicly visible but still sensitive. The lack of stronger safeguards and transparency undermines trust and leaves millions potentially exposed to phishing, scam, possibly identity theft, and long-term privacy issues,” the team said.


Threat actors can find multiple uses for a dataset of that size, as it allows cybercriminals to easily automate attacks, unleashing armies of bots targeting each and every user in the dataset with little manual effort. Knowing that email addresses in the dataset belong to Facebook users, malicious actors can target them with one of the numerous Facebook phishing scams.


Threat actors often attempt to exploit APIs for nefarious purposes. Earlier this year, attackers targeted APIs of Shopify, GoDaddy, Wix and OpenAI. Financially motivated actors often attempt to abuse the same technique to get themselves into cryptocurrency wallets.


    “Repeated incidents show a pattern of reactive rather than proactive security measures, particularly when it comes to protecting data that’s publicly visible but still sensitive,”
    researchers said.


Most popular services couldn't exist without APIs as they serve as a way for different services to communicate with each other. However, attackers find ways to use legitimate APIs for nefarious purposes, such as fetching way more data than the software programs were intended to.


Scraping data from Facebook is nothing unheard of. For example, last year, Meta admitted to scraping public Facebook and Instagram data to train its AI virtual assistant.


Meanwhile, in 2021, another attacker posted information like phone numbers and locations on over 500 million Facebook users. The leak got Meta in trouble as the European Union's top data privacy regulator, the Irish Data Protection Commission (DPC), fined the company €265 million ($266 million).


Source:
CyberNews
https://cybernews.com/security/facebook-...ers-claim/
This post is by a banned member (HIGHTORQUE) - Unhide
504
Posts
333
Threads
2 Years of service
#2
UPDATEAfter Hackread.com’s news coverage of the “1.2 billion Facebook database” went live and major outlets like DailyMail, TechRadar, MSN, Times of India and many others picked it up, the forum where the supposed information was being sold began arguing about the authenticity of the data.
As we had questioned its legitimacy, it turned out to be fake. The supposed hacker was revealed to be a scammer with a history of changing their Telegram username, reappearing under a new identity, and launching new scams. The post has now been deleted, and the scammer has been permanently banned from the forum.

[Image: threat-actor-selling-1-2-billion-faceboo...s-scam.jpg]


A key takeaway: most of these so-called “database sellers” are scammers, and media outlets should treat their claims with scepticism, especially when they involve a company like META.

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 1 Guest(s)