Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Have I Been Pwned Adds Search For Leaked Facebook Phone Numbers

Have I Been Pwned Adds Search For Leaked Facebook Phone Numbers

Facebook users can now use the Have I Been Pwned data breach notification site to check if their phone number was exposed in the social site’s recent data leak.

Last weekend, a threat actor released a data leak containing information for 533 million Facebook users. This information includes phone numbers and Facebook IDs for almost all exposed accounts and other optional information such as a member’s name, gender, relationship status, location, occupation, date of birth, and email address.

This data was initially collected in 2019 and sold privately at the time. Over time, the data was traded and sold between different threat actors for lower and lower prices until it was eventually released for free on the hacker forum this weekend.

​Facebook data leak released on a hacking forum
​Facebook data leak released on a hacking forum

When it was released, the data was added to the Have I Been Pwned data breach notification service so that users can look up whether their emails were in the Facebook data leak.

However, this leak’s main component is a Facebook user’s phone number, rather than an email address, and thus Have I Been Pwned could not accurately alert a user if they were exposed in the breach.

“There’s over 500M phone numbers but only a few million email addresses so >99% of people were getting a “miss” when they should have gotten a “hit”,” Have I Been Pwned creator Troy Hunt explained in a blog post.

To more accurately alert users, Hunt has updated Have I Been Pwned so that users can now search for their phone numbers on the site to determine if the leak exposed their Facebook info.

Also Read: 4 Best Practice On How To Use SkillsFuture Credit

When searching for phone numbers, users must include their country code as that is how the data leak stored the number.

For example, in the sample of exposed New York users below, the phone numbers start with the country code of 1, followed by the person’s full number.

Sample of leaked Facebook users from New York
Sample of leaked Facebook users from New York

For example, if you wanted to check if your phone number was part of the Facebook data leak, you would need to use a search in the format ‘19175555555.’ If you are in the UK, you would need to include your country code as well, so a searchable phone number format would be ‘+442071838750.’

Hunt states that the + symbol is optional and will be stripped when searching, as shown below.

Searching Have I Been Pwned with a phone number
Searching Have I Been Pwned with a phone number

With this new feature added, Have I Been Pwned has become a valuable tool for Facebook members to determine if the data leak exposed their data.

Unfortunately, when data leaks such as this one are released, it is common for other threat actors to use this information in their own attacks.

Also Read: 3 Reasons Why You Must Take A PDPA Singapore Course

If your data was exposed, you should be on the lookout for Facebook phishing emails or smishing (phishing texts) attacks that attempt to harvest more information from you.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us