Skip to content
City PM
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
Sunday 09 August 2015 10:43 pm

Facebook hack: Security flaw allows hackers to harvest personal data using only a phone number

By: Clara Guibourg

Add as a preferred source on Google

Facebook has come under fire for lax user data security, as a software engineer was able to extract personal information about thousands of users from the social media company.

With thousands of users’ names, photos, location settings and phone numbers leaking out through a security loophole, Facebook has been called upon to tighten its privacy settings.

The data was harvested using a little-known search feature which allows you to search for any Facebook user using only their phone number.

A software engineer discovered this feature and, keen to explore it, wrote an algorithm that generated thousands of numbers automatically. Sending these numbers through Facebook’s application programming interface (API), user profiles and personal data soon began pouring in.

All of the data is publicly available, but as there is no limit to the number of searches an individual user can make, the loophole could be used by cyber crooks to extract information about “millions” of users, according to the engineer Reza Moaiandin, technical director of Leeds-based company Salt.agency. Writing on the company blog, he said the loophole was discovered “by mistake”:

By using a script, an entire country’s (I tested with the US, the UK and Canada) possible number combinations can be run through these URLs, and if a number is associated with a Facebook account, it can then be associated with a name and further details

Moaiandin has alerted Facebook to the security flaw, and a spokesperson told him “We do not consider it a security vulnerability, but we do have controls in place to monitor and mitigate abuse.”

The “Who can search for me?” setting is set to public by default, meaning that even if your mobile number is withheld on the site, it can still be used to find you using this loophole.

A Facebook spokesperson told City PM that this is set to public so that they can more easily be found by friends, and that users' privacy was "extremely important" to the company:

We have industry leading proprietary network monitoring tools constantly running in order to ensure data security and have strict rules that govern how developers are able to use our APIs to build their products. Developers are only able to access information that people have chosen to make public.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech

Related Topics

  • Cybercrime
  • Facebook

Trending Articles

  • Top Burnham adviser calls for capital gains and inheritance tax hikes

  • A meeting with the breakfast king of Mayfair

  • Clarkson’s Farm and why businesses must stop blaming the weather

  • FTSE 100 Live: Stocks jump on defence and metals boost; Oil on track to shed a fifth on US-Iran peace hopes

  • BT tops FTSE 100 after finding new home for international business with Verizon joint venture

More from City PM

  • ‘Safe’ version of Anthropic’s Mythos model hits market

    Tech
    Anthropics AI technology showcased at a tech conference, highlighting innovative advancements in artificial intelligence
  • Musk brands UK a ‘police state’ as Big Tech rebels against Starmer’s social media ban

    Tech
    Getty Images logo on a digital screen, symbolizing media and photography industry presence in news and business contexts
  • VPN demand rockets as UK prepares for under-16 social media ban

    Tech
    Getty Images logo on a digital screen, symbolizing media and photography industry presence in news and business contexts
  • UK Pupils and Students Aren’t the Only Ones Feeling Exam Pressure – Universities Are Too, with £2Bn at Stake

    Business Wire
  • GoldenSource Unveils Next-Generation AI-Powered Data Intelligence Platform for Financial Services

    Business Wire
  • Neo4j Acquires GraphAware to Launch Intelligence Analysis Alternative to Palantir Gotham

    Business Wire
  • Starmer’s social media restrictions will mean the government can spy on every phone

    Opinion
    Keir Starmer at tech event discussing innovation and policy, surrounded by tech leaders and digital displays
  • Social media ban may push children to ‘darker corners of the internet,’ lawyers warn

    Legal
    Australia's policy, which came into force in December and bars children under 16 from major platforms including Tiktok, Instagram, Snapchat and X.

City PM — European politics, business and analysis.

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Topics

  • Business
  • Markets
  • AI
  • Technology
  • Opinion
  • Energy

More

  • Politics
  • Economics
  • Fintech
  • Legal
  • Sport
  • Life

Company

  • About City PM
  • Editorial Policy
  • Corrections
  • Contact
  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 City PM · Published by CityPM Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
About · Editorial Policy · Corrections · Contact · Privacy