A Chinese data-scraping social media management firm named Socialaarks has exposed over 200 million users of Instagram, Facebook, and LinkedIn, as its entire 408 GB of data leaked online. The security incident resulted from an ElasticSearch server misconfiguration, which was set to public access without password protection. The exposed set includes public data as well as private information including phone numbers and email addresses. In detail, the researchers have found the following in the exposed server: 11,651,162 Instagram user profiles, 66,117,839 LinkedIn user profiles, and 81,551,567 Facebook user profiles.

Pravin Rasiah
January 12, 2021
VP of Product
CloudSphere

A platform that provides a holistic view into the cloud landscape minimizes the potential attack surface.

Instagram, LinkedIn, and Facebook are three major social media platforms containing a plethora of user data, and this incident underscores the perils of data scraping without proper security. Since personally identifiable information was found bundled together with commonalities between profiles, it amplifies the risk of this data being abused by hackers and scammers. For example, for some individuals impacted, there is more than enough information exposed for bad actors to launch highly

Instagram, LinkedIn, and Facebook are three major social media platforms containing a plethora of user data, and this incident underscores the perils of data scraping without proper security. Since personally identifiable information was found bundled together with commonalities between profiles, it amplifies the risk of this data being abused by hackers and scammers. For example, for some individuals impacted, there is more than enough information exposed for bad actors to launch highly targeted phishing attacks.

 

Leaving a database like this exposed without password protection is often the result of improper security and access management policies or failure to enforce those policies. To prevent incidents like this from occurring, organizations must implement a comprehensive set of security tools that monitor and control security status in real-time. A platform that provides a holistic view into the cloud landscape minimizes the potential attack surface, shares security and access alerts in real-time, and avoids devastating misconfigurations that put sensitive data at risk.

