Feeds

One million Facebook users' names and email addresses: $5

An effective way to fight social network fraud: Priceless

5 things you didn’t know about cloud backup

Name and email addresses of Facebook users are available online at prices as low as $5 per million.

The dodgy trade was uncovered by Bogomil Shopov, an internet marketeer and blogger in the Czech Republic. Shopov said he approached the social network about the problem. He said Facebook asked him to forward and then delete the data, which came in the form on a compressed spreadsheet. Facebook representatives also wanted to know where he'd bought the data and what payment systems were used, he said, adding that he had been happy to answer.

However, the Czech blogger said he objected to requests he says were made by the Facebook representatives to keep his conversations with with them about the matter a secret. He said Facebook told him it was running an internal legal investigation but dragged its feet when it came to promising to advise users about how to avoid their data ending up in the hands of unscrupulous data brokers. "I asked if it was possible to tell what the problem was, after they finished the investigation, so that the users could protect themselves, but they they emphasised that it would be an internal investigation and they would not share any information with third parties," Shopov wrote in an updated blog post.

Shopov suspects the Facebook data, which contained Facebook profile URLs as well as email addresses and names on users of the social network, came from a third-party developer. Shopov said ads advertising the sale of the data were pulled soon after he tipped Facebook off about the issue. The Czech blogger was able to verify that at least some of the email addresses contained in the list were accurate.

Although internet services marketing site gigbucks.com has removed the offending ad, it can still be viewed via Google cache here, Ars Technica reports.

Shopov told El Reg that other sites are offering Facebook data for sale. "I know two so far and it seems the part of the data is (was) available in a post in Facebook," he said.

In a statement, Facebook said early indications were that the data was scraped from its site before being bundled with other information and sold online, probably illegally.

Facebook is vigilant about protecting our users from those who would try to expose any form of user information. In this case, it appears someone has attempted to scrape information from our site and combine the information with data publicly available elsewhere on the web.

We have dedicated security engineers and teams that look into, and take aggressive action on reports just like these. In addition to the engineering teams that build tools to block scraping we also have a dedicated enforcement team that seeks to identify those responsible for breaking our terms and works with our legal team to ensure appropriate consequences follow.

We continue to investigate this specific individual.

Shopov told El Reg that he didn't believe the data was scraped from Facebook. Whoever is behind the scam can expect to face sanctions from Facebook, up to and including the possibility of criminal prosecution.

Thriving trade in black market likes

In other Facebook-related security news, Imperva warned that it had uncovered a bustling trade in social network fraud on an online black market it monitors. The 250,000-member hacker forum plays host to a thriving black market for buying and selling illegitimate social network "Likes", followers, and endorsements, with particular attention given to the origin of these Likes and followers.

"Likes and followers can be used to gain rank, win competitions, and many other causes that can often be translated to monetary profit," Imperva explains. "Many forum discussions contain requests to buy Facebook friends and Likes, Twitter followers and other types of social currency. There are, of course, many who are willing to provide the service, for variable prices."

A thousand Facebook Likes can be easily purchased for $10 or less, with discounts for bulk purchases.

Imperva's report on the hacker forum, published on Tuesday, can be found here (PDF). ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
JLaw, Kate Upton exposed in celeb nude pics hack
100 women victimised as Apple iCloud accounts reportedly popped
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
Oz fed police in PDF redaction SNAFU
Give us your metadata, we'll publish your data
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.