Facebook data breach: Private messages, photos and check-ins could be leaked

Security experts fear Facebookâs latest data breach could lead to usersâ photos, private conversations and even check-ins being leaked publicly online.
The social media giant revealed on Friday that the private information of more than 50 million users had been exposed after attackers exploited a feature that allowed them to take over usersâ accounts.
Facebook said in a post that the security issue was related to the âView Asâ feature, which allows people to see a preview of what their profile looks like to other people, like specific friends.
Dr Muhammad Usman, data and cyber security expert at Swinburne University, said Facebookâs latest data breach could result in usersâ personal information such as emails and passwords being leaked online on paste websites such as Pastebin.Â
Websites such as Have I Been Pwned allow users to see if their accounts have been compromised on these paste sites.
âItâs possible that usersâ personal information could end up on these sites, especially if theyâve used their Facebook account to log in into other third-party apps,â Dr Usman told The New Daily.
âFacebook are not taking the proper precautions to secure usersâ account details, so itâs important for people to be mindful of what kind of personal information theyâre posting including private chats.â
Deakin Universityâs Cyber Security Research Institute professor Matt Warren said Facebookâs data breach meant usersâ private conversations, photos and even check-ins could be exposed.
âSeveral users use a federated log in with Tinder, Spotify and Instagram, meaning their Facebook account can be used to log them in on those sites,â Dr Warren told The New Daily.
âThe biggest risk with this is that usersâ photos, data and location details could have been harvested in this breach.â
Dr Warren said the sophistication of the breach could lead to identity theft.
âWe could start seeing a trend of fake accounts using peopleâs posts and photos,â he said.
âOn the dark net this data could be used as a potential way to make money by blackmailing users or it could be used as a harvest for email addresses to launch spam attacks.â
The hack comes amid intense scrutiny over Facebookâs role in the Cambridge Analytica scandal in April, where the private information of 87 million users was illegally obtained by a British political consulting firm.
What can you do to protect your data?
Security experts told The New Daily it was critical for users to take simple steps to ensure their account details didnât end up in the wrong hands.
Change your password
Facebook says that because it has fixed the vulnerability, there is no need to change your account password, but security experts disagree because thereâs still a strong risk of accounts linked to third-party apps such as Tinder, Spotify, and Instagram being compromised.Â
Experts also recommend users sign up to third-party apps with their email address and not their Facebook account to ensure their information isnât shared among platforms.
Turn on two-factor authentication
Facebook and other social media platforms offer a security feature called two-factor authentication. It involves sending a unique code to your phone that you must type in after entering your password.Â
Conduct an online auditÂ
Users can see if theyâve fallen victim to other online security breaches on sites such as Have I Been Pwned. If this is the case, then itâs highly recommended to change your password on all accounts linked to the compromised email account.Â
On Facebookâs Security and Login page, under the tab labelled âWhere Youâre Logged in,â you can see a list of devices that are signed into your account, as well as their locations.
If you see an unfamiliar device signed in at an unrecognised location, you can click the âRemoveâ button to remove the device from your account.








