
Security researchers disclosed on April 3, 2019 that two collections of Facebook-related information had been left in publicly accessible Amazon Web Services storage. The larger collection, held by Mexican digital publisher Cultura Colectiva, contained more than 540 million records in a 146-gigabyte database. Anyone who knew where to look could reach the storage bucket without a password.
The figure described records, not necessarily 540 million distinct people. A single user could appear many times through comments, reactions or other activity. Even with that qualification, the scale was extraordinary. UpGuard said the dataset included Facebook account names and identifiers as well as information about comments, likes, reactions and other interactions.
Two different exposures
UpGuard also discovered a smaller public bucket associated with At the Pool, a Facebook-connected application that had shut down years earlier. That collection held data on roughly 22,000 users, including names, email addresses, friend information and passwords. The passwords appeared to belong to the At the Pool application rather than to Facebook itself, but people who reused credentials on other services could still have faced additional risk.
The cases were not described as hackers breaking into Facebook’s own network. Third parties had obtained information through Facebook integrations and then stored it insecurely. That distinction explained the technical route, but it did little to reassure users. Once a platform had allowed an outside developer to collect data, Facebook could not retroactively control every copy.
A slow path to removal
UpGuard said it emailed Cultura Colectiva on January 10 and again on January 14 without receiving a response. It then contacted Amazon Web Services, which notified the bucket owner. The data remained accessible, leading researchers to alert Facebook in early April. The Cultura Colectiva bucket was secured on April 3 after media organizations began asking questions. The At the Pool collection disappeared while UpGuard was investigating it.
Facebook said its policies prohibited storing Facebook information in a public database and that, once notified, it worked with Amazon to take the material down. Cultura Colectiva said the information had been gathered from fan-page interactions and was not sensitive. Yet public comments and reactions can become much more revealing when collected, indexed and tied to persistent identifiers in bulk.
The larger platform problem
The discovery followed the Cambridge Analytica scandal and intensified scrutiny of Facebook’s former developer ecosystem. For years, apps could accumulate data for games, quizzes, sign-ins and community tools. Closing an interface or changing a policy did not erase datasets already exported by thousands of developers. Misconfigured cloud storage added another weak point: Amazon supplied security controls, but customers remained responsible for enabling them correctly.
There was no public proof in April 2019 that criminals had downloaded or abused these two collections. An exposed database, however, cannot produce a complete visitor log showing that nobody copied it. The appropriate response was therefore to secure the buckets, investigate access and review every similar third-party repository.
For users, the episode was a reminder to limit unnecessary app permissions, remove old Facebook integrations and avoid reusing passwords. For platforms, it showed that privacy responsibility extends beyond the moment of collection. If partners can retain enormous archives without effective auditing or deletion, tightening the front door does not protect data already scattered outside it.
Recent Comments