Facebook sues data analytics firm for harvesting users data

According to the lawsuit, OneAudience improperly accessed and collected user data from Facebook and other social media companies by paying App developers to install a malicious Software Development Kit (SDK) in their apps.

February 28, 2020 10:11 am | Updated November 28, 2021 11:33 am IST

File photo.

File photo.

Facebook has filed a federal lawsuit in California court against New Jersey-based data analytics firm OneAudience for secretly harvesting its users’ data.

According to the lawsuit, OneAudience improperly accessed and collected user data from Facebook and other social media companies by paying App developers to install a malicious Software Development Kit (SDK) in their apps.

“After a user installed one of these apps on their device, the malicious SDK enabled OneAudience to collect information about the user from their device and their Facebook, Google, or Twitter accounts, in instances where the user logged into the app using those accounts,” read the lawsuit.

Security researchers first flagged OneAudience’s behaviour to Facebook as part of its data abuse bounty programme.

Facebook, and other affected companies, then took enforcement measures against OneAudience.

“Facebook’s measures included disabling apps, sending the company a cease and desist letter, and requesting their participation in an audit, as required by our policies. OneAudience declined to cooperate,” said Jessica Romero, Director of Platform Enforcement and Litigation.

“This is the latest in our efforts to protect people and increase accountability of those who abuse the technology industry and users,” she added.

In November last year, Facebook and Twitter admitted that data of hundreds of users was improperly accessed by some third-party apps on Google Play Store as they logged into those apps.

Security researchers discovered that OneAudience and Mobiburn provided access to users’ data, including email addresses, usernames, and recent tweets, on both the platforms.

Twitter and Facebook said they will notify those whose information was likely shared through apps.

Facebook has sued several third-party platforms in the recent past for scrapping users’ data, including Israeli surveillance vendor NSO Group that sells malicious software Pegasus to government agencies.

 

“Through these lawsuits, we will continue sending a message to people trying to abuse our services that Facebook is serious about enforcing our policies, including requiring developers to cooperate with us during an investigation, and advance the state of the law when it comes to data misuse and privacy,” said the company.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.