Losing Face: Two More Cases of Third-Party Facebook App Data Exposure

siteadmin August 27, 2020

The UpGuard Cyber Risk team has discovered data from two Facebook apps left exposed on the internet. One dataset, from Mexico-based Cultura Colectiva, was 146GB and held over 540m records including comments, reactions, account names and Facebook IDs. A backup from defunct Facebook-integrated app At the Pool contained plaintext passwords for 22,000 users, along with many other details. Both datasets were stored in a publicly accessible Amazon S3 bucket.