Tuesday, April 22, 2025
HomeInternet25,936 Malicious Apps Use Facebook APIs to Obtain a Range of Information

25,936 Malicious Apps Use Facebook APIs to Obtain a Range of Information

Published on

SIEM as a Service

Follow Us on Google News

25,936 malicious apps currently using facebook login or messaging API, capable of obtaining a range of information from the Facebook profile such as name, location, and email address.

The Cambridge Analytica data-gathering scandal is mainly due to permissions abused by the developers that associated with the Facebook Login feature. 87 Million Facebook Users Affected by the Cambridge Analytica Data Scandal.

After this incident, Facebook has made some import decision and changes in Facebook products Such as Events API, Groups API, Pages API, Facebook Login, and other Functions.

- Advertisement - Google News

Also Read Key Elements and Important Steps to General Data Protection Regulation (GDPR)

Trustlook discovered 25,936 malicious apps based on the App Insights that scans for apps around the world and provides 80 pieces of information for each app, including permissions, libraries, risky API calls, network activity, and risk score.

“When people use Facebook Login, they grant the app’s developer a range of information from their Facebook profile. Back in 2015, Facebook also allowed developers to collect some information from the friend networks of people who used Facebook Login.” reads Trustlook statement.

Trustlook Spokesperson told Threatpost that all the 25,936 malicious apps can do the same thing that led to Cambridge Analytica issue. All the identified malicious apps having risk score 7, it might do things like capturing pictures and audio when the app is closed or making an unusually large amount of network calls.

Earlier this week it was reported that Twitter sold data access to the Cambridge University academic who also obtained millions of Facebook Inc.

According to Twitter, “In 2015, GSR(Global Science Research) did have one-time API access to a random sample of public tweets from a five-month period from December 2014 to April 2015.Based on the recent reports, we conducted our own internal review and did not find any access to private data about people who use Twitter.”

“To be fair, Facebook is not the only company with its APIs embedded in malicious applications. Twitter, LinkedIn, Google, and Yahoo offer similar options to developers, and thus their user data faces similar exposure.” reads Trustlook statement.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Japan Sounds Alarm Over Hackers Draining Millions from Compromised Trading Accounts

Cybersecurity in Japan has hit a new low as the Financial Services Agency (FSA)...

FBI Alerts Public to Scammers Posing as IC3 Officials in Fraud Scheme

The Federal Bureau of Investigation (FBI) has issued a warning regarding an emerging scam...

CISA Issues Warning Against Using Censys, VirusTotal in Threat Hunting Ops

 The Cybersecurity and Infrastructure Security Agency (CISA) has alerted its threat hunting teams to...

PoC Released for Critical Unauthenticated Erlang/OTP RCE Vulnerability

A critical remote code execution (RCE) vulnerability in Erlang/OTP’s SSH implementation (CVE-2025-32433) has now...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

FBI Alerts Public to Scammers Posing as IC3 Officials in Fraud Scheme

The Federal Bureau of Investigation (FBI) has issued a warning regarding an emerging scam...

New ‘Waiting Thread Hijacking’ Malware Technique Evades Modern Security Measures

Security researchers have unveiled a new malware process injection technique dubbed "Waiting Thread Hijacking"...

EU’s GDPR Article 7 Poses New Challenges for Businesses To Secure AI-Generated Image Data

As businesses worldwide embrace digital transformation, the European Union’s General Data Protection Regulation (GDPR),...