https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2022 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Channel Partners 101 (CP 101)
  • Events
    • Back
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Security


Shutterstock

Facebook Security

Dumped Facebook Users’ Personal Information Ripe for Cyberattacks

  • Written by Edward Gately
  • April 5, 2021
The Facebook user data was released this weekend practically for free.

The cellphone numbers and other personal information of 533 million Facebook users from 106 countries has been posted online. Cybercriminals can use the information to launch attacks.

Alon Gal, CTO of cybersecurity firm Hudson Rock, tweeted about the data dump this weekend. The United States had 32.3 million affected users and United Kingdom had 11.5 million.

All 533,000,000 Facebook records were just leaked for free.

This means that if you have a Facebook account, it is extremely likely the phone number used for the account was leaked.

I have yet to see Facebook acknowledging this absolute negligence of your data. https://t.co/ysGCPZm5U3 pic.twitter.com/nM0Fu4GDY8

— Alon Gal (Under the Breach) (@UnderTheBreach) April 3, 2021

The released data includes Facebook users’ mobile numbers, name, gender, location, relationship status, occupation, date of birth and email addresses.

According to Bleeping Computer, the data was originally sold in private sales after being collected in 2019 using a bug in the “Add Friend” feature on Facebook. Facebook closed this vulnerability soon after discovering it. But threat actors continued to circulate the data until it was practically free over the weekend, it said.

Unscrupulous Scammers Will Use All the Information They Can Get

Purandar Das is CEO and co-founder at Sotero.

Sotero Software's Purandar Das

Sotero’s Purandar Das

“This makes you wonder as to how much of that information ends up in the legitimate marketing industry,” he said. “It only takes a few vendors to integrate this data into the broader data set the marketing industry uses. Mobile numbers and Facebook handles are typically in pretty high demand. Of course, the unscrupulous scammers will use every bit of information they can get in their scams.”

Setu Kulkarni is is vice president of strategy at WhiteHat Security. He calls the data dump “the tsunami of the past.”

WhiteHat Security's Setu Kulkami

WhiteHat Security’s Setu Kulkami

“While Facebook has fixed the issue, the damage of exfiltration of sensitive data occurred before the vulnerability was fixed,” he said. “Considering that millions of phone numbers are out in the open, along with enough personal data about the phone number owners, it is likely that there will be a spike in smishing. Now more than ever, it is important to seriously reconsider using phone numbers as logins or sharing phone numbers with apps. Switching phone numbers is inordinately more taxing than switching email IDs.”

Common Attack Pattern

Michael Isbitski is technical evangelist at Salt Security. He said content scraping is a common attack pattern. At the very least, the data is useful to attackers for phishing campaigns and social engineering, he said.

Salt Security's Michael Isbitski

Salt Security’s Michael Isbitski

“Organizations must protect their APIs and monitor consumption continuously in order to catch such malicious activity as content scraping or authorization bypasses,” Isbitski said. “API security issues can also expose organizations to regulatory penalties, since many standards and legislation … explicitly define types of personal identifiable information (PII) that must be protected. This includes phone numbers and account identifiers as seen in the leaked Facebook data sets.”

Cybercriminals can combine even seemingly innocuous types of data to uniquely identify individuals and impact privacy, he said.

No Surprise

Digital Shadows' Ivan Righi

Digital Shadows’ Ivan Righi

Ivan Righi is a cyber threat intelligence analyst at Digital Shadows. He said it’s not a surprise that this data leak has resurfaced. Few threat actors could buy the data when it it initially carried a relatively steep price.

“The breach was probably resold multiple times since then until the price lowered enough that a user decided to publicly expose it to generate a small profit and increase reputation,” he said. “This activity frequently happens in criminal forums. While the data may be old, it still holds a lot of value to cybercriminals.”

It is likely most phone numbers are still active and remain linked to legitimate Facebook users, Righi said. Cybercriminals can use information such as phone numbers, emails and full names to launch targeted social engineering attacks. Those include phishing, vishing or spam.

Cybercriminals may find success with most people working from home, he said.

“For example, cybercriminals could send text messages impersonating companies or banks to users,” Righi said. “These messages could name the individual within the text to add credibility and include malicious links.”

Tags: MSPs VARs/SIs Best Practices Mobility & Wireless Regulation & Compliance Security Strategy

Most Recent


  • Cyber insurance
    Now Is the Time to Consider Cyber Insurance for Your Business
    If your business is online and accesses sensitive data, the need for cyber insurance is becoming critical.
  • Telarus leadership team
    Images: Telarus Hosts Partner Summit, Gives Partner, Supplier Awards
    See who landed Telarus' top partner award.
  • Making Waves
    7 Channel People Making Waves This Week at Kaseya, AT&T, Cohesity, More
    Cloud-managed service is the fastest-growing area one analyst said in response to an MSP acquisition this week.
  • Job cuts
    RingCentral Announced Layoffs Ahead of Strong Earnings Growth in Q2
    RingCentral says changing business needs necessitate the job cuts.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • edge computing
    'Challenging Results' for MSPs in Channel Futures' Exclusive Quarterly Survey
  • White House
    White House Urges Companies to Take Ransomware Attacks More Seriously
  • Security shield on digital background
    VMware Security Connect Focused on Redefining Security, Increasing Threats
  • Fortune 500 2021 logo
    AT&T, Microsoft, Verizon, More Tech, Telco Companies Make Latest Fortune 500

Upcoming Events

View all

MSP Summit

September 13, 2022 - September 16, 2022

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Galleries

View all

Images: Telarus Hosts Partner Summit, Gives Partner, Supplier Awards

August 5, 2022

7 Channel People Making Waves This Week at Kaseya, AT&T, Cohesity, More

August 5, 2022

The Gately Report: Zscaler Tracks New, Increasingly Dangerous Ransomware Group, Most Targeted Types of People

August 5, 2022

Industry Perspectives

View all

Seize the Application Modernization Opportunity

August 2, 2022

A Growth Mindset: Your Organization’s Strategic Differentiator

August 1, 2022

Timely Tips for Non-Negotiable Patch Updates

July 29, 2022

Webinars

View all

Outsmarting RaaS: Implementation Strategies To Help Your Clients Before, During, and After a Ransomware Attack

August 23, 2022

Why it is Important to Upgrade Aging Servers and How to use Live Optics to Upgrade Efficiently

August 25, 2022

Executives at Home are Not Alright: An Intro to Digital Executive Protection

September 8, 2022

White Papers

View all

Work Goes Remote – (and Other Top ITOps Trends)

May 25, 2022

The New Bottom Line: How MSPs Can Meet the Healthcare Crisis While Evolving Their Businesses

April 19, 2022

How to build a Security Operations Center (on a budget)

April 4, 2022

Channel Futures TV

View all

Vonage a ‘Single Communications Stack Provider’ for Partners, Customers

IBM, Partners and the $1 Trillion Hybrid Cloud Opportunity

June 26, 2022

Agents Share ‘Secrets,’ Industry Opportunity

May 11, 2022

AT&T, Microsoft, Cisco, ThreatLocker on Unlocking Partner Potential

May 6, 2022

Twitter

ChannelFutures

.@ConnectWise says use #cyberinsurance policies to protect from worst of cyberattack repercussions, but first beef… twitter.com/i/web/status/1…

August 8, 2022
ChannelFutures

Check out our pictures from the #TelarusPartnerSummit that @telarus hosted in Salt Lake City.… twitter.com/i/web/status/1…

August 5, 2022
ChannelFutures

Channel People Making Waves This Week Include: @spoonen, @RoyArsan, @TheAnneChow, @AnuragTechaisle… twitter.com/i/web/status/1…

August 5, 2022
ChannelFutures

.@RingCentral plans #layoffs after strong Q2 earnings. dlvr.it/SW7kd5 https://t.co/OIlLuYgyLJ

August 5, 2022
ChannelFutures

.@msftsecurity makes upgrades to #MicrosoftDefender. dlvr.it/SW7cpg https://t.co/KbPsyM8eYe

August 5, 2022
ChannelFutures

.@ZeroFox goes public after #SPAC merger. #cybersecurity dlvr.it/SW7NjC https://t.co/IhaO9vgDh7

August 5, 2022
ChannelFutures

.@Mitel's new developer portal, and integration into CloudLink, creates a "vibrant" communications developer commun… twitter.com/i/web/status/1…

August 5, 2022
ChannelFutures

Boost security, secure #SoftwareSupplyChain in light of #Log4Shell breach, says @synopsys. dlvr.it/SW7GbT https://t.co/NlKeEFUlMS

August 5, 2022

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2022 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X