235 million Youtube, TikTok and Instagram users’ data exposed

The data exposed has information that includes profile name, full real name, profile picture, account description, and whether the profile belongs to a business or has advertisements. 20 % of the total records collected had phone number or email address.

August 25, 2020 10:19 am | Updated 10:34 am IST

Attackers can easily access the data during such exposures, Comparitech said

Attackers can easily access the data during such exposures, Comparitech said

Personal data of 235 million Youtube, TikTok and Instagram users were disclosed in a data breach, said Comparitech, a cybersecurity research firm.

Social Data, a company that sells data on social media influencers to marketers, has exposed a database of social media profiles on the web without a password or any other authentication required to access it, said Bob Diachenko, who leads Comparitech’s cybersecurity research team.

The data exposed has information that includes profile name, full real name, profile picture, account description, and whether the profile belongs to a business or has advertisements. 20 % of the total records collected had phone number or email address.

It also had statistics on account followers like number of followers, engagement rate, and audience gender, age, and location.

Comparitech said that the scammers can use the images and other profile data to create fake accounts, which can attract followers and then promote misinformation. The images can also be used in face recognition systems without the owners’ consent.

Comparitech is not sure if the data was exposed before they identified this on August 1, and if any unauthorised parties accessed the data during the exposure. The database was shut down nearly three hours after the cyber research firm disclosed it.

According to evidence, much of the data came from a now-defunct company Deep Social.

Diachenko reached out to them and disclosed the exposure. The administrators of Deep Social forwarded it to Social Data which took down the servers hosting the data.

Facebook and Instagram had banned Deep Social from their marketing APIs in 2018 and threatened legal action if it continued to scrape data from their users’ profiles.

Despite Deep Social shutting down its operations since then, the practice has not ceased as pointed out by researchers.

Web scraping is an automated task that copies data and information from web pages in bulk. Social media companies are having a tough time to prohibit the automated scraping bots to access users’ profiles as it is difficult to distinguish between them and normal website visitors, Comparitech said.

Although Social Data said that it only scrapes publicly accessible information, that practice violates the policies of Facebook, Instagram, TikTok, and Youtube.

“Scraping people’s information from Instagram is a clear violation of our policies,” Facebook said.

However Social data blamed the social networks for exposing data themselves to the outsiders. Anyone could phish or contact any person who have indicated their phone numbers and e-mail id on their social network profiles description even without the existence of the database and any secret hacking, it said. Those users who do not wish to provide information, must make their accounts private.

Top News Today

Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.