The social media giant says it did not access the imported data and is notifying affected users.
Facebook has confirmed it "unintentionally uploaded" email contacts belonging to 1.5 million new users without their knowledge since May 2016. It is now deleting the information.
This discovery, first reported by Business Insider, began when a security researcher realized Facebook was requesting email passwords to verify some users' identities during the account creation process. If the password was entered, users saw an alert informing them Facebook was importing their contacts – even though the site hadn't requested permission to do so.
As Facebook explained, prior to May 2016 it gave users the option to input their email passwords to verify their accounts and upload contacts. The idea was to use the imported data for better advertising and recommending friends to users. When the company changed this feature, it eliminated the language telling people their contacts would be uploaded. However, the functionality remained and has been importing data from email accounts ever since.
The social media giant says it didn't access the uploaded data and is informing people whose contacts were uploaded. That said, it's worth noting how many individuals' information may have been affected. This feature uploaded the contacts of 1.5 million users, many of whom could have had information belonging to hundreds of people in their email address books.
Read more details here.
Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.
About the Author(s)
You May Also Like
Guarding the Cloud: Top 5 Cloud Security Hacks and How You Can Avoid Them
April 4, 2024Cybersecurity Strategies for Small and Med Sized Businesses
April 11, 2024Defending Against Today's Threat Landscape with MDR
April 18, 2024Securing Code in the Age of AI
April 24, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024Black Hat Asia - April 16-19 - Learn More
April 16, 2024