Facebook Says Login Data Can Be Hijacked

Mark Zuckerberg

Facebook has more data issues to worry about this week. This time it’s a security research report that shows the site’s user data can be taken by third-party JavaScript trackers embedded on websites using Login with Facebook.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    yesSubscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    The social media company has confirmed to TechCrunch that it’s investigating the report.

    According to the research, trackers are able to gather a user’s data – including name, email address, age range, gender, location and profile photo – depending on what users initially provided to the website.

    The scripts were found on 434 of the top 1 million websites, including Fiverr.com and MongoDB.

    “We were unaware that a third-party technology was using a tracking script that collects parts of Facebook user data. We have identified the source of the script and shut it down,” MongoDB said when contacted about the report.

    It is unclear what the trackers are doing with the data once they obtain it.

    Advertisement: Scroll to Continue

    In addition, it was discovered that the concert site Bandsintown has been passing login with Facebook user data to embedded scripts on sites that install its Amplified advertising product, which then leads to the ability for any malicious site using Bandsintown to learn the identity of visitors.

    “Bandsintown does not disclose unauthorized data to third parties, and upon receiving an email from a researcher presenting a potential vulnerability in a script running on our ad platform, we quickly took the appropriate actions to resolve the issue in full,” Bandsintown said in a statement.

    This news comes at a bad time for Facebook, which is dealing with fallout from the revelation that data of 87 million users may have been improperly shared with Cambridge Analytica.

    In addition, CEO Mark Zuckerberg admitted under questioning that Facebook also collects “data of people who have not signed up for Facebook,” claiming the practice was done for security purposes.