Computer security

309 million Facebook users personal data is sold on the Dark Web

According to Cyble researchers, 309 million Facebook users profile are being sold in Dark Web for around $540 USD per record. The details include Facebook user IDs, phone numbers, relationship status, email addresses, timestamps of recent connectivity, and age. Passwords aren’t exposed, but this data exposure can facilitate phishing or spear phishing campaigns to trigger further exploitation of the users data.  

How was the Facebook users data exposed?

As per Cyble report, the data could have been exposed by a leak in Facebook’s developer API or from scraping. 

However, this data exposure has multiple existing threads already. Bob Diachenko, a security researcher have spotted the same data exposure by taking down the ISP hosting page and had 42 million records in a elastic search cluster on a different server, and was removed by some unknown entity. Diachenko had partnered with Comparitech (a software review and comparison platform) to identify the database and also discovered it was exposed publicly for almost two weeks now.

Source: Comparitech

Below is the timeline for the overall facebook data exposure, 

Initially the data included only 267 million users and restricted to the US region, however, later 42 million new records were added to this collection.

Below is the fattened database that was exposed,

Source: Comapritech

Stop sharing everything on social media

Though Facebook’s third party developer API had some loopholes, the researchers believe that this data exposure could be more of a scrapping methodology. Stop sharing every personal information on social media, and ensure you have got your privacy settings verified. 

In Facebook, navigate to the Settings & Privacy, and verify your current privacy settings, and update most of it to friends or only me, and also remove search engines outside of Facebook to link your profile. 

Though the hackers hadn’t discovered the passwords yet, this is not a huge milestone for them, as a simple email address and exposed passwords search in the dark web could deliver them a handful of relevant passwords to try on, so if you are using the same passwords for multiple login platforms, then its a jackpot for the cyber criminals.

Four best practices to secure your Facebook account

  1. Activate two-factor authentication right away.
  2. Ensure your passwords are strong, alphanumerical with special characters and case-sensitive characters.
  3. Update your passwords every 60 days, and especially after reading this article update it to the earliest, (If you’re from the United States, update it right away)
  4. Verify your privacy settings, remove unknown contacts, and ensure you accept friend request only if you know the person personally. (This is because Facebook is known for fake accounts and scammers, data exposure to fake accounts can also make your data compromised)

Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on FacebookLinkedinInstagramTwitter and Reddit.

Share the article with your friends
William Marshal

William has been one of the key contributors to 'The Cybersecurity Times' with 9.5 years of experience in the cybersecurity journalism. Apart from writing, he also like hiking, skating and coding.

View Comments

  • Like!! I blog frequently and I really thank you for your content. The article has truly peaked my interest.

  • Thanks so much for this list. Made our lives easier. This list of commenting sites is especially useful for digital marketers who have been assigned off-page activity. Backlinks and keywords play an important role in SEO. Roxine Stanislaus Amaleta

  • Mi dui, tincidunt id venenatis vel, luctus quis lorem. Curabitur a ante non leo eleifend pretium. Vivamus efficitur ex varius dignissim imperdiet. Max Brent Attlee

  • Have you ever considered creating an ebook or guest authoring on other sites? I have a blog based upon on the same information you discuss and would really like to have you share some stories/information. I know my audience would appreciate your work. If you are even remotely interested, feel free to shoot me an email.| Janeva Gabriel Charmion

  • I appreciate you sharing this blog post. Really looking forward to read more. Much obliged. Kassia Willem Bouton

  • What a stuff of un-ambiguity and preserveness of precious experience regarding unpredicted emotions. Florette Nahum Merrilee

  • The travel companies always take advantage of school holidays to increase the cost of supply because of high demand. Jolee Mic Tobi

  • I think you have noted some very interesting points , thankyou for the post. Kipp Locke Fowler Margy Lonnie Belita

Recent Posts

Best Microsoft Intune Alternatives: Top 5 MDMs to Consider

Explore the top 5 best Microsoft Intune alternatives, comparing key features, user reviews, and capabilities…

1 day ago

Top 7 Best Smartphones with Best Security Features in 2024

Discover the top 7 smartphones of 2024 with best security features, offering privacy, performance, and…

3 weeks ago

Top 11 Log Management Tools for Efficient System Management

Discover the top 11 log management tools for efficient system management and monitoring. Learn about…

2 months ago

Top 5 Threat Intelligence Tools For 2024

Explore the top 5 threat intelligence tools, their features, and how they enhance cybersecurity against…

2 months ago

Privileged Access Management: 5 Best PAM Solutions in the Market

Explore the top 5 best PAM Tools, market trends, and expert insights to secure the…

2 months ago

Apple Device Management: Top Solutions for iOS and macOS Management

Explore the top solutions for Apple Device Management including to iOS Device Management and macOS…

2 months ago