{"id":14568,"date":"2018-11-02T12:31:32","date_gmt":"2018-11-02T16:31:32","guid":{"rendered":"https:\/\/www.kaspersky.co.in\/blog\/facebook-leak-browser-extensions\/14568\/"},"modified":"2020-02-26T20:29:32","modified_gmt":"2020-02-26T14:59:32","slug":"facebook-leak-browser-extensions","status":"publish","type":"post","link":"https:\/\/www.kaspersky.co.in\/blog\/facebook-leak-browser-extensions\/14568\/","title":{"rendered":"New leakage of Facebook user data, including private messages"},"content":{"rendered":"<p>Little more than a month has passed since the last <a target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/facebook-token-breach\/24052\/\" rel=\"noopener noreferrer nofollow\">major Facebook data breach<\/a>, and now there is more unpleasant news for users of the social network. Using malicious browser extensions, cybercriminals are alleged to have harvested the data of tens of millions of people, including private messages.<\/p>\n<h2>What happened?<\/h2>\n<p>A <a target=\"_blank\" href=\"https:\/\/www.bbc.com\/news\/technology-46065796\" rel=\"noopener noreferrer nofollow\">BBC investigation<\/a> reported that an online forum was offering to sell the personal data of 120 million Facebook users, at 10 cents per individual profile. To prove the value of the data, a small part of the database was made publicly available, consisting of data for 257,000 users, including the private messages of about a third (81,000) of them.<\/p>\n<p>The claim that 120 million accounts are at risk of exposure cannot, of course, be confirmed or refuted without access to the full version of the database. However, according to the BBC journalists who checked the data, everything appears to suggest that the leaked portion of the archive is real.<\/p>\n<h2>Is this linked to the Facebook leak a month ago?<\/h2>\n<p>Apparently, the breaches are unrelated. The earlier <a target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/facebook-token-breach\/24052\/\" rel=\"noopener noreferrer nofollow\">incident<\/a> involved the use of Facebook vulnerabilities for centralized, \u201cwholesale\u201d data theft. But in the latest case, data was harvested using malicious browser extensions that the victims had installed on their own computers. This is a different ball game altogether.<\/p>\n<h2>Malicious browser extensions? What\u2019s that all about?<\/h2>\n<p>Extensions (also known as plug-ins or add-ons) are small programs that are installed \u201con top\u201d of the browser, extending its functionality. Examples include toolbars that change the browser interface, ad blockers, and so forth. The problem with these extensions is that they can \u2014 and most of them do, as part of their regular operation \u2014 see all the content that browser is showing you (and change it too, for that matter).<\/p>\n<p>This ability makes them highly adept at tracking the user\u2019s online movements and collecting various data. The case at hand is about data harvested from Facebook pages. But in principle, any information can be stolen this way. Banking data, for example, <a target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/malicious-chrome-extension\/\" rel=\"noopener noreferrer nofollow\">is also far from immune<\/a>. See the post \u201c<a target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/browser-extensions-security\/20886\/\" rel=\"noopener noreferrer nofollow\">Why you should be careful with browser extensions<\/a>\u201d for more details.<\/p>\n<p>It is not yet clear, and may never be, which extensions were used in the latest Facebook data breach. So, other data might have been stolen; we don\u2019t know that yet.<\/p>\n<p>At present, we can make two general recommendations based on this story:<\/p>\n<ul>\n<li>Treat browser extensions seriously, and don\u2019t install them indiscriminately. These days, pretty much all of our most valuable information is available on a handful of websites, and extensions <a target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/browser-extensions-security\/20886\/\" rel=\"noopener noreferrer nofollow\">have access to it<\/a>.<\/li>\n<li>Be more prudent when it comes to private correspondence online. It might be far less private than you think.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The personal data of 257,000 Facebook users, including private messages belonging to 81,000 of them, has leaked online. Hackers claim to have access to 120 million accounts.<\/p>\n","protected":false},"author":421,"featured_media":14434,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1855,2196],"tags":[1252,16,1470,20,21,1173,363,417],"class_list":{"0":"post-14568","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-privacy","8":"category-threats","9":"tag-browsers","10":"tag-chrome","11":"tag-extensions","12":"tag-facebook","13":"tag-firefox","14":"tag-leaks","15":"tag-personal-data","16":"tag-plugins"},"hreflang":[{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/facebook-leak-browser-extensions\/14568\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/facebook-leak-browser-extensions\/12196\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/facebook-leak-browser-extensions\/16502\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/facebook-leak-browser-extensions\/14712\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/facebook-leak-browser-extensions\/13608\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/facebook-leak-browser-extensions\/17269\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/facebook-leak-browser-extensions\/16540\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/facebook-leak-browser-extensions\/21619\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/facebook-leak-browser-extensions\/5387\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/facebook-leak-browser-extensions\/24496\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/facebook-leak-browser-extensions\/11118\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/facebook-leak-browser-extensions\/11034\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/facebook-leak-browser-extensions\/10002\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/facebook-leak-browser-extensions\/18046\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/facebook-leak-browser-extensions\/21926\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/facebook-leak-browser-extensions\/17571\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/facebook-leak-browser-extensions\/21447\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/facebook-leak-browser-extensions\/21447\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.co.in\/blog\/tag\/facebook\/","name":"Facebook"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts\/14568","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/users\/421"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/comments?post=14568"}],"version-history":[{"count":5,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts\/14568\/revisions"}],"predecessor-version":[{"id":19398,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts\/14568\/revisions\/19398"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/media\/14434"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/media?parent=14568"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/categories?post=14568"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/tags?post=14568"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}