Breached Facebook Database For Sale on DarkWeb

NJCCIC Alert

Original Release Date: 4/24/2020

Summary

Approximately 267 million Facebook records have been found available for purchase on a dark web hacker’s forum for $615 worth of bitcoin. The data appears to be from a misconfigured Elasticsearch server discovered in December 2019. Most of these records belong to US Facebook users and contain various forms of information such as profile links, full names, email addresses, phone numbers, ages, dates of birth, and addresses. Though the breach does not appear to include account passwords, threat actors may attempt to use this information to conduct various forms of social engineering attacks such as spear-phishing and smishing. Additionally, threat actors can easily weaponize information shared by users on social media. Oftentimes, information that is thought to be innocuous – such as a pet’s name or mother’s maiden name – can reveal common password retrieval security questions, as described in the FBI Charlotte Field Office post.

Recommendations

The NJCCIC recommends users exercise caution when opening unsolicited emails and text messages. Additionally, we advise users to review social media privacy and security settings, exercise caution when sharing information, and enable multi-factor authentication where available. Users can also check haveibeenpwned to discover if account credentials or information may have been compromised in other data breaches. Further information can be found in the HackRead article.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.