Feeds

One million Facebook users' names and email addresses: $5

An effective way to fight social network fraud: Priceless

High performance access to file storage

Name and email addresses of Facebook users are available online at prices as low as $5 per million.

The dodgy trade was uncovered by Bogomil Shopov, an internet marketeer and blogger in the Czech Republic. Shopov said he approached the social network about the problem. He said Facebook asked him to forward and then delete the data, which came in the form on a compressed spreadsheet. Facebook representatives also wanted to know where he'd bought the data and what payment systems were used, he said, adding that he had been happy to answer.

However, the Czech blogger said he objected to requests he says were made by the Facebook representatives to keep his conversations with with them about the matter a secret. He said Facebook told him it was running an internal legal investigation but dragged its feet when it came to promising to advise users about how to avoid their data ending up in the hands of unscrupulous data brokers. "I asked if it was possible to tell what the problem was, after they finished the investigation, so that the users could protect themselves, but they they emphasised that it would be an internal investigation and they would not share any information with third parties," Shopov wrote in an updated blog post.

Shopov suspects the Facebook data, which contained Facebook profile URLs as well as email addresses and names on users of the social network, came from a third-party developer. Shopov said ads advertising the sale of the data were pulled soon after he tipped Facebook off about the issue. The Czech blogger was able to verify that at least some of the email addresses contained in the list were accurate.

Although internet services marketing site gigbucks.com has removed the offending ad, it can still be viewed via Google cache here, Ars Technica reports.

Shopov told El Reg that other sites are offering Facebook data for sale. "I know two so far and it seems the part of the data is (was) available in a post in Facebook," he said.

In a statement, Facebook said early indications were that the data was scraped from its site before being bundled with other information and sold online, probably illegally.

Facebook is vigilant about protecting our users from those who would try to expose any form of user information. In this case, it appears someone has attempted to scrape information from our site and combine the information with data publicly available elsewhere on the web.

We have dedicated security engineers and teams that look into, and take aggressive action on reports just like these. In addition to the engineering teams that build tools to block scraping we also have a dedicated enforcement team that seeks to identify those responsible for breaking our terms and works with our legal team to ensure appropriate consequences follow.

We continue to investigate this specific individual.

Shopov told El Reg that he didn't believe the data was scraped from Facebook. Whoever is behind the scam can expect to face sanctions from Facebook, up to and including the possibility of criminal prosecution.

Thriving trade in black market likes

In other Facebook-related security news, Imperva warned that it had uncovered a bustling trade in social network fraud on an online black market it monitors. The 250,000-member hacker forum plays host to a thriving black market for buying and selling illegitimate social network "Likes", followers, and endorsements, with particular attention given to the origin of these Likes and followers.

"Likes and followers can be used to gain rank, win competitions, and many other causes that can often be translated to monetary profit," Imperva explains. "Many forum discussions contain requests to buy Facebook friends and Likes, Twitter followers and other types of social currency. There are, of course, many who are willing to provide the service, for variable prices."

A thousand Facebook Likes can be easily purchased for $10 or less, with discounts for bulk purchases.

Imperva's report on the hacker forum, published on Tuesday, can be found here (PDF). ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
Bad PUPPY: Undead Windows XP deposits fresh scamware on lawn
Installing random interwebs shiz will bork your zombie box
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.