As elaborated in a blog post by Comparitech, the researchers discovered an unsecured Elasticsearch cluster that included millions of users’ data.
Specifically, the total exposed records sum up to 267,140,436, the information predominantly belonged to the US users. The exposed details included users’ full name, unique Facebook ID, phone number, and time stamp events.
Upon finding the open database, Diachenko swiftly reported the matter to the ISP managing the IP address of the server. After his report, the database went offline.
Though, the researcher also found the same data available for sale on a hackers’ forum. So, it might be possible that the data, or part of the exposed data, could be available elsewhere.
Diachenko recommends setting Facebook profile visibility to private, that is, not indexed with search engines, to avoid public scraping.
Furthermore, users should also avoid setting the visibility of various details on their profile to ‘public’. These security measures are particularly important considering the fact that such incidents have also happened in the past.
Let us know your thoughts in the comments.