Meta suffered a data privacy breach after dozens of employees and contractors — including Meta security guards revealed they were improperly accessing users’ accounts.
The employees and contractors wrongly used Facebook’s internal mechanism for helping password-forgetting users reclaim their accounts.
They even assisted third parties to fraudulently take control over Instagram accounts.
The Meta fired the employees as soon as it got to know about the incident.
TPRM report: https://scoringcyber.rankiteo.com/company/meta
"id": "met1717151222",
"linkid": "meta",
"type": "Breach",
"date": "11/2022",
"severity": "100",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Social Media',
'name': 'Meta',
'type': 'Corporation'}],
'attack_vector': 'Insider Threat',
'data_breach': {'type_of_data_compromised': 'User account data'},
'description': 'Meta suffered a data privacy breach after dozens of employees '
'and contractors — including Meta security guards — revealed '
'they were improperly accessing users’ accounts.',
'impact': {'data_compromised': 'User account data'},
'motivation': 'Unauthorized access to user accounts and assisting third '
'parties',
'response': {'remediation_measures': 'Firing of employees involved'},
'threat_actor': ['Employees', 'Contractors', 'Security Guards'],
'title': 'Meta Data Privacy Breach',
'type': 'Data Privacy Breach',
'vulnerability_exploited': 'Internal mechanism for helping '
'password-forgetting users reclaim their accounts'}