Cyber agency asks Indian FB users to enhance account privacy after global data leak

A cyber security expert had spoken about this online leak earlier this month, which was acknowledged by the company, stating that “this is old data that was previously reported on in 2019. We found and fixed this issue in August 2019”.

Updated - April 20, 2021 06:37 pm IST

Published - April 20, 2021 06:05 pm IST

Cyber agency asks Indian FB users to enhance account privacy after global data leak.

Cyber agency asks Indian FB users to enhance account privacy after global data leak.

(Subscribe to our Today's Cache newsletter for a quick snapshot of top 5 tech stories. Click here to subscribe for free.)

The country's cyber security agency CERT-In has advised Facebook users to strengthen their account privacy settings after a recent global 'data scraping' incident in the social media platform affected about 61 lakh Indians.

"As the Facebook platform evolves and grows, parts of your account could be public. Data could also be collected and shared in ways you don't know about," the Indian Computer Emergency Response Team or CERT-In said in a public advisory issued on Monday.

It is the federal technology arm to combat cyber attacks and guard the Indian cyber space against phishing and hacking assaults and similar online attacks.

"It has been reported that globally there has been a large scale leakage of Facebook profile information. The exposed information includes email addresses, profile ID, full name, job occupation, phone numbers and birth date. "According to Facebook, the scraped information does not include financial information, health information or passwords, however information from more than 450 million unique Facebook profiles globally, including approximately 61 lakh Indian individuals, has been made publicly available in multiple cyber criminal forums for free," the advisory said while explaining the breach.

Also Read | Explained | How Facebook’s recent data breach affect its users

A cyber security expert had spoken about this online leak earlier this month, which was acknowledged by the company, stating that "this is old data that was previously reported on in 2019. We found and fixed this issue in August 2019". The CERT-In said that Facebook has claimed that this 'data scraping' happened by using the "contact importer" feature of the platform, which allows users to find other users by using their phone numbers.

"Facebook stated that this feature was changed in September 2019, following the discovery that threat actors were abusing the feature.

"However, while Facebook modified the feature in 2019 to thwart this kind of abuse, the phone numbers of 450 million global users had already been harvested by malicious actors, along with other identifying information on users," it said.

Also Read | Ireland launches inquiry into Facebook after reports of data leak

Dejargonising the term 'data scraping' , the advisory said it refers to the process of using automated software or scripts to harvest public information from sites, such as any information users make publicly available in their profiles like names, city, occupation, among others.

"Cyber criminals may scrape data from sites for a variety of purposes, including spamming, information gathering and social engineering attacks.

"They can also sell scrapped data for a profit to other cyber criminals, marketing companies or call centres," it said.

The advisory, while asking users of this popular social media platform to follow good cyber hygiene practices, also said that Facebook has advised individuals to "make sure that their privacy settings reflect what information they want to share publicly and who they want to be able to look them by phone number".

Also Read | Instagram, Facebook, and LinkedIn share over 50% user data with third party firms, study says

Facebook, it added, has also recommended account holders to enable two-factor authentication also know as 2FA.

It also recommended that users can consider changing their profile settings to "private" or "friends" only as data scrapers can use "public" information of an individual to "match and combine with data from other breaches to access even more of their personal information and accounts".

It also asked users to adjust their settings to who can find and contact them on Facebook and consider whether to set them all to "friends" or stricter for stronger security.

Also Read | The Cambridge Analytica saga: The Hindu explains

In a similar incident reported in March 2018, Facebook data of over 5.62 lakh Indians was allegedly compromised as UK-based Cambridge Analytica had accessed information of about 87 million users globally. The Central Bureau of Investigation (CBI) is now probing this data breach on charges of profiteering and manipulating elections by illegal harvesting of Indian user data.

India is among the biggest markets for Facebook and its group companies, WhatsApp and Instagram and according to government data, the country has 41 crore Facebook users, 53 crore WhatsApp users and 21 crore users of Instagram.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.