Millions of Facebook Records Exposed on Amazon Cloud Servers - MacRumors
Skip to Content

Millions of Facebook Records Exposed on Amazon Cloud Servers

Millions of Facebook records were found on publicly accessible Amazon's cloud servers by researchers at UpGuard, a cybersecurity firm, reports Bloomberg. The data was uploaded by third-party companies that work with Facebook.

Mexico City-based media company Cultura Colectiva, for example, was storing 540 million records on Facebook users on Amazon's servers, offering up information that included identification numbers, comments, reactions, and account names.

facebooksecurity
A now-defunct app called At the Pool shared sensitive data like names and email addresses for 22,000 Facebook users.

Facebook did not leak this data, but it did provide the data to the third-party companies that went on to improperly store it with no oversight from Facebook. For years, Facebook provided extensive customer information to advertisers and partners, and while the company has since cracked down on the amount of data it shares, the previously obtained information is still widely available.

"The public doesn't realize yet that these high-level systems administrators and developers, the people that are custodians of this data, they are being either risky or lazy or cutting corners," said Chris Vickery, director of cyber risk research at UpGuard. "Not enough care is being put into the security side of big data."

Facebook's prior data sharing habits allowed any app on the site to obtain information from the people using the app and their friends in many cases, which led to the scandal that saw Cambridge Analytica illicitly using personal data acquired from Facebook to create targeted political advertisements in the 2016 election.

Facebook has since modified its privacy policies and has cut down on the access that apps have. Facebook has also suspended hundreds of apps and began audits to make sure data isn't being mishandled.

In response to the public Facebook data found by UpGuard, a Facebook spokesperson told Bloomberg that its policies prohibit the storing of Facebook information in a public database, though there is apparently little oversight from Facebook. Facebook did work with Amazon to take down the databases that were sharing data publicly after UpGuard's discovery.

Popular Stories

iOS 26

iOS 26.4 Adds Two New Features to CarPlay

Tuesday March 24, 2026 1:55 pm PDT by
iOS 26.4 was released today, and it includes a couple of new features for CarPlay: an Ambient Music widget and support for voice-based chatbot apps. To update your iPhone 11 or newer to iOS 26.4, open the Settings app and tap on General → Software Update. CarPlay will automatically offer the new features so long as the iPhone connected to your vehicle is running iOS 26.4 or later....
Apple Business hero

Apple Unveils 'Apple Business' All-in-One Platform

Tuesday March 24, 2026 8:53 am PDT by
Apple today announced Apple Business, a new all-in-one platform that unifies device management, productivity tools, and customer outreach features. The service is designed to be a consolidated replacement for several of Apple's existing business-focused offerings, including Apple Business Essentials, Apple Business Manager, and Apple Business Connect. It provides organizations with a single...
AirPods Pro Firmware Feature

Apple Releases New Firmware for AirPods Pro 3, AirPods Pro 2 and AirPods 4

Tuesday March 24, 2026 12:31 pm PDT by
Apple today released new firmware for the AirPods Pro 2, AirPods Pro 3, and the AirPods 4. The firmware has a version number of 8B39, up from 8B34 on the AirPods Pro 3, 8B28 on the AirPods Pro 2, and 8B21 on the AirPods 4. There is no word on what's included in the firmware, but Apple has a support document with limited notes. Most updates are limited to bug fixes and performance...

Top Rated Comments

cmaier Avatar
91 months ago
Another day, another facebook data scandal.
Score: 52 Votes (Like | Disagree)
91 months ago
Everything you post on facebook is public. There's no such thing as a private post, period. You have to treat facebook like that.
Score: 17 Votes (Like | Disagree)
91 months ago
Just when you think Facebook has hit rock bottom they somehow manage to dive off of another cliff
Score: 15 Votes (Like | Disagree)
91 months ago
this site should be renamed to apple/facebook fails
Score: 14 Votes (Like | Disagree)
jsmith189 Avatar
91 months ago
I use Facebook with a complete understanding that any and everything on there is being sold and likely improperly used. Instagram too. That's why I don't link credit cards and FB has its own individual password. Having said that, I know apps share their data too, so FB probably have it all anyway.

Zuck is the literal devil.
Score: 9 Votes (Like | Disagree)
91 months ago
I have no huge love for Facebook, but this article title is blatantly false. Facebook didn't expose millions of records on Amazon's cloud servers, one of their 3rd party partners did, and the article states that in the first line, so why is the title "Facebook Exposes Millions of Records on Amazon Cloud Servers"??

The article also craps on Facebook saying there's "apparently little oversight from Facebook", as if to imply that they'd somehow be able to stop these 3rd parties from mismanaging their data, but how could they possibly know what and where their data is being stored once it leaves their APIs? The company violated Facebook's T&C's, I'm not sure how they'd have the authority or ability to "audit" that.

EDIT: CNN's title for the same article is "Hundreds of millions of Facebook records exposed on Amazon cloud servers". That seems much more appropriate?
Score: 5 Votes (Like | Disagree)