The attack exposed the personal information of many users, including their names, phone numbers, dates of birth, and more.
Such information could be used for identity theft and to compromise users’ financial and other accounts, security and privacy experts say.
Exposing such data can also pose obvious dangers to people trying to go unnoticed, such as victims of domestic violence.
If you are one of the victims of the Facebook hack, you should be very careful on the internet and pay attention to your other accounts, both online and not.
The data obtained could be used for identity theft, and to access bank accounts and other financial institutions to online stores. They can also be used in phishing attacks, in which hackers use the information they know about certain users to send them messages that end up convincing them to leak their passwords or other critical data.
“Given the escalation of the hacking and the amount of information that was stolen … people may be legitimately concerned,” said Justin Brookman, director of privacy and technology policy for Consumers Union, the publisher of Consumer Reports.
Facebook first disclosed the attack two weeks ago. There are 30 million accounts compromised. Hackers were able to access the names and phone numbers of nearly all of those users, as well as personal data such as dates of birth, marital status, gender, and education and work histories of 14 million of them. You may hire an ethical hacker here hire an Instagram hacker
Exposing this type of personal data can be especially dangerous for people trying to go unnoticed, such as those who have been victims of domestic abuse or protesters concerned about retaliation from their governments. It can also create problems for anyone trying to keep certain parts of their life private from the world at large, such as their sexual orientation or religious affiliations.
Facebook data can be used to access bank accounts
But it can also be a risk for everyday users: in the hands of malicious actors, this data can be used to hijack accounts on other services, not just Facebook.
The password reset feature on many sites asks users to answer certain security questions. Those questions often ask the kind of personal data that was exposed in the Facebook hack, Brookman said.
But it’s not just online accounts that are at risk. Information such as names and dates of birth can also be used to access bank accounts or medical records over the phone, says John Simpson, director of privacy and technology for Consumer Watchdog, a consumer advocacy group. That kind of information “can be tremendously powerful” for hackers.
Even leaking just one phone number can pose a risk. To protect their accounts on various websites, many users activate two-factor authentication, a security technique that often requires users to enter a special code in addition to their passwords when logging into their accounts. Many sites send that code via SMS to users’ phones.
However, security researchers have known for years that the SMS system is vulnerable to attack. By knowing a user’s phone number, a malicious actor could intercept the two-factor authentication code and use it to gain control of their account.
It can also be used in specific email attacks.
Another potential danger comes from phishing attacks. In such attacks, a hacker sends an email that prompts a user to click on a link to a spoofed site and enter their login information. The malicious actor often uses what he knows about the target – his friends, his family, his life experiences – to convince him that the email is legitimate.
Even the most innocuous information about a person is used in such attacks. The more data a hacker has about someone, the more credible they will be. One of the data sets that was exposed in the hack was that of the locations where users had registered using the Facebook application.
A hacker could take that information and say that it is a representative of a user’s credit card company, giving information such as that the company knows that their card has been used on that date and place, said Michelle Richardson, director of the project. privacy and data at the Center for Democracy and Technology, a support group.
What can you do to protect yourself?
You can find out if the attack on Facebook affected you by logging into your account and accessing a security page that the company has set up.
If you are one of those affected, follow these steps to protect yourself:
Freeze your credit report with major credit reporting agencies, like Equifax. This will prevent criminals from using the information to create new financial accounts in your name.
Keep an eye on your accounts for suspicious charges.
Make sure you are not using the same password in multiple places.
Activate two-factor authentication whenever you can, but especially on your most sensitive or valuable accounts. Even those systems that can be vulnerable to hacking attacks are still more secure than passwords alone.
Regardless of whether your account was affected, you may also want to consider deleting or deactivating your Facebook account, especially if you don’t use it frequently.
“People share things on their Facebook profiles that they would not like to share with the rest of the world,” Brookman said. He continued: “There is historical data that exists about you that could potentially be exploited against you or used to hack your account or compromise that of your friends.”
