Skip to main content

Socialbot gang ‘steals’ personal data from 3,000+ Facebook users

facebook-privacy
Image used with permission by copyright holder

A ‘socialbot’ may have stolen your personal Facebook data, reports The Register. But don’t worry, the digital hoard was unleashed in the name of science. 

A team of student researchers at the University of British Columbia Vancouver released 102 socialbots – software that mimics real users – into Facebook to test the social network’s ability to combat against such menace. 

The so-called “socialbot network,” or SbN, sent out a total of 8,570 connection requests, during a period of 8 weeks. The requests went to a total of about 5,000 randomly selected Facebook users, according to the group’s research paper (pdf), which will be presented at the Annual Computer Security Applications Conference in Orlando, Florida, next month. 

The bots were able to automatically gather 250GB of personal user data from 3,055 Facebook members who mistakenly accepted friend requests from the fake user profiles. The fake profiles included a fake photograph, as well as status updates pulled directly from iheartquotes.com. Most of the data obtained by the SbN was intended to be seen only by users’ friends, and included 46,500 email addresses and more than 14,500 home addresses.

About 20 percent of the SbN socialbots were detected by the Facebook Immune System, which is designed to automatically detect fake profiles, though most of the detection was due to users reporting the fake accounts as spam, the report says. 

Facebook, of course, is not happy about the experiment, and says it is concerned about the methodology used by the researchers.

“We have numerous systems designed to detect fake accounts and prevent scraping of information. We are constantly updating these systems to improve their effectiveness and address new kinds of attacks,” a Facebook spokesperson said in a statement to media outlets.

“We use credible research as part of that process. We have serious concerns about the methodology of the research by the University of British Colombia and we will be putting these concerns to them.

“In addition, as always, we encourage people to only connect with people they actually know and report any suspicious behavior they observe on the site.”

The research team addresses the ethical concerns of the experiment, but concluded that they were justified in their actions. 

“Online social network’s security defences, such as the Facebook Immune System, are not effective enough in detecting or stopping a large-scale infiltration as it occurs,” the team wrote in the report. 

“We believe that large-scale infiltration in online social networks is only one of many future cyber threats, and defending against such threats is the first step towards maintaining a safer social web for millions of active web users.”

Unlike traditional botnets, which are controlled by people who then steal data from users’ computers, the SbN was controlled automatically by a ‘botmaster’ program. A single socialbot can be purchased for about $29. 

Editors' Recommendations

Topics
Andrew Couts
Former Digital Trends Contributor
Features Editor for Digital Trends, Andrew Couts covers a wide swath of consumer technology topics, with particular focus on…
Bluesky barrels toward 1 million new sign-ups in a day
Bluesky social media app logo.

Social media app Bluesky has picked nearly a million new users just a day after exiting its invitation-only beta and opening to everyone.

In a post on its main rival -- X (formerly Twitter) -- Bluesky shared a chart showing a sudden boost in usage on the app, which can now be downloaded for free for iPhone and Android devices.

Read more
How to make a GIF from a YouTube video
woman sitting and using laptop

Sometimes, whether you're chatting with friends or posting on social media, words just aren't enough -- you need a GIF to fully convey your feelings. If there's a moment from a YouTube video that you want to snip into a GIF, the good news is that you don't need complex software to so it. There are now a bunch of ways to make a GIF from a YouTube video right in your browser.

If you want to use desktop software like Photoshop to make a GIF, then you'll need to download the YouTube video first before you can start making a GIF. However, if you don't want to go through that bother then there are several ways you can make a GIF right in your browser, without the need to download anything. That's ideal if you're working with a low-specced laptop or on a phone, as all the processing to make the GIF is done in the cloud rather than on your machine. With these options you can make quick and fun GIFs from YouTube videos in just a few minutes.
Use GIFs.com for great customization
Step 1: Find the YouTube video that you want to turn into a GIF (perhaps a NASA archive?) and copy its URL.

Read more
I paid Meta to ‘verify’ me — here’s what actually happened
An Instagram profile on an iPhone.

In the fall of 2023 I decided to do a little experiment in the height of the “blue check” hysteria. Twitter had shifted from verifying accounts based (more or less) on merit or importance and instead would let users pay for a blue checkmark. That obviously went (and still goes) badly. Meanwhile, Meta opened its own verification service earlier in the year, called Meta Verified.

Mostly aimed at “creators,” Meta Verified costs $15 a month and helps you “establish your account authenticity and help[s] your community know it’s the real us with a verified badge." It also gives you “proactive account protection” to help fight impersonation by (in part) requiring you to use two-factor authentication. You’ll also get direct account support “from a real person,” and exclusive features like stickers and stars.

Read more