Saturday, March 8, 2025
HomeInternet25,936 Malicious Apps Use Facebook APIs to Obtain a Range of Information

25,936 Malicious Apps Use Facebook APIs to Obtain a Range of Information

Published on

SIEM as a Service

Follow Us on Google News

25,936 malicious apps currently using facebook login or messaging API, capable of obtaining a range of information from the Facebook profile such as name, location, and email address.

The Cambridge Analytica data-gathering scandal is mainly due to permissions abused by the developers that associated with the Facebook Login feature. 87 Million Facebook Users Affected by the Cambridge Analytica Data Scandal.

After this incident, Facebook has made some import decision and changes in Facebook products Such as Events API, Groups API, Pages API, Facebook Login, and other Functions.

Also Read Key Elements and Important Steps to General Data Protection Regulation (GDPR)

Trustlook discovered 25,936 malicious apps based on the App Insights that scans for apps around the world and provides 80 pieces of information for each app, including permissions, libraries, risky API calls, network activity, and risk score.

“When people use Facebook Login, they grant the app’s developer a range of information from their Facebook profile. Back in 2015, Facebook also allowed developers to collect some information from the friend networks of people who used Facebook Login.” reads Trustlook statement.

Trustlook Spokesperson told Threatpost that all the 25,936 malicious apps can do the same thing that led to Cambridge Analytica issue. All the identified malicious apps having risk score 7, it might do things like capturing pictures and audio when the app is closed or making an unusually large amount of network calls.

Earlier this week it was reported that Twitter sold data access to the Cambridge University academic who also obtained millions of Facebook Inc.

According to Twitter, “In 2015, GSR(Global Science Research) did have one-time API access to a random sample of public tweets from a five-month period from December 2014 to April 2015.Based on the recent reports, we conducted our own internal review and did not find any access to private data about people who use Twitter.”

“To be fair, Facebook is not the only company with its APIs embedded in malicious applications. Twitter, LinkedIn, Google, and Yahoo offer similar options to developers, and thus their user data faces similar exposure.” reads Trustlook statement.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

10 Best Penetration Testing Companies in 2025

Penetration testing companies play a vital role in strengthening the cybersecurity defenses of organizations...

Lumma Stealer Using Fake Google Meet & Windows Update Sites to Launch “Click Fix” Style Attack

Cybersecurity researchers continue to track sophisticated "Click Fix" style distribution campaigns that deliver the...

Fake BianLian Ransom Demands Sent via Physical Letters to U.S. Firms

In a novel and concerning development, multiple U.S. organizations have reported receiving suspicious physical...

Strela Stealer Malware Attack Microsoft Outlook Users for Credential Theft

The cybersecurity landscape has recently been impacted by the emergence of the Strela Stealer...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

49,000+ Access Management Systems Worldwide Exposed to Major Security Gaps

A recent study conducted by Dutch IT security consultancy Modat has revealed alarming vulnerabilities...

Chinese Hackers Breach Belgium State Security Service as Investigation Continues

Belgium’s State Security Service (VSSE) has suffered what is being described as its most...

Check Point Software to Open First Asia-Pacific R&D Centre in Bengaluru, India

Check Point Software Technologies Ltd. has announced plans to establish its inaugural Asia-Pacific Research...