Cultura Colectiva, a digital media publisher, reportedly stored more than 540 million records—including activity and account names—without a password, meaning anyone could access the data. And, a backup file from At The Pool, a now-defunct California-based app maker, had records including scraped data on over 22,000 users of its apps, including their names, passwords, email addresses and Facebook IDs. The two data sets were stored on separate Amazon cloud servers. Facebook said there was no evidence the information had been misused, but that it contacted Amazon to put the data offline. (TechCrunch, UpGuard)
Talking point: Though the exposed data would not exist without Facebook, it is not under the platform’s control; the third parties to whom it was transferred are responsible for its security. Third-party use of data is what landed the social media platform in its current public relations mess after it was reported that political data firm Cambridge Analytica allegedly harvested information on users through a quiz app. Facebook has since cut down on the number of apps that can access user data. It also expanded its bug bounty program—under which researchers are paid to identify security vulnerabilities—to third-party services connected to the platform.