Skip to main content
  1. Home
  2. Social Media
  3. Legacy Archives

Socialbot gang ‘steals’ personal data from 3,000+ Facebook users

Add as a preferred source on Google
facebook-privacy
Image used with permission by copyright holder

A ‘socialbot’ may have stolen your personal Facebook data, reports The Register. But don’t worry, the digital hoard was unleashed in the name of science. 

A team of student researchers at the University of British Columbia Vancouver released 102 socialbots – software that mimics real users – into Facebook to test the social network’s ability to combat against such menace. 

Recommended Videos

The so-called “socialbot network,” or SbN, sent out a total of 8,570 connection requests, during a period of 8 weeks. The requests went to a total of about 5,000 randomly selected Facebook users, according to the group’s research paper (pdf), which will be presented at the Annual Computer Security Applications Conference in Orlando, Florida, next month. 

The bots were able to automatically gather 250GB of personal user data from 3,055 Facebook members who mistakenly accepted friend requests from the fake user profiles. The fake profiles included a fake photograph, as well as status updates pulled directly from iheartquotes.com. Most of the data obtained by the SbN was intended to be seen only by users’ friends, and included 46,500 email addresses and more than 14,500 home addresses.

About 20 percent of the SbN socialbots were detected by the Facebook Immune System, which is designed to automatically detect fake profiles, though most of the detection was due to users reporting the fake accounts as spam, the report says. 

Facebook, of course, is not happy about the experiment, and says it is concerned about the methodology used by the researchers.

“We have numerous systems designed to detect fake accounts and prevent scraping of information. We are constantly updating these systems to improve their effectiveness and address new kinds of attacks,” a Facebook spokesperson said in a statement to media outlets.

“We use credible research as part of that process. We have serious concerns about the methodology of the research by the University of British Colombia and we will be putting these concerns to them.

“In addition, as always, we encourage people to only connect with people they actually know and report any suspicious behavior they observe on the site.”

The research team addresses the ethical concerns of the experiment, but concluded that they were justified in their actions. 

“Online social network’s security defences, such as the Facebook Immune System, are not effective enough in detecting or stopping a large-scale infiltration as it occurs,” the team wrote in the report. 

“We believe that large-scale infiltration in online social networks is only one of many future cyber threats, and defending against such threats is the first step towards maintaining a safer social web for millions of active web users.”

Unlike traditional botnets, which are controlled by people who then steal data from users’ computers, the SbN was controlled automatically by a ‘botmaster’ program. A single socialbot can be purchased for about $29. 

Andrew Couts
Features Editor for Digital Trends, Andrew Couts covers a wide swath of consumer technology topics, with particular focus on…
Topics
New X phishing scam uses fake login alerts to steal your account
Scammers have copied X's own security emails almost pixel for pixel, and people are falling for it.
X app store listing on iPhone

You open your inbox and see an alert claiming someone just logged into your X account from an unfamiliar device. Your first instinct is to click through and lock things down immediately. That instinct is exactly what a new phishing scam is counting on.

As reported by The Guardian, a wave of fake X security emails is currently doing the rounds. They claim a new device has logged into your account and urge you to click a link to reset your password or review app access. 

Read more
After YouTube, TikTok is testing its own AI likeness detection tool
TikTok's new tool lets creators flag AI deepfakes of themselves directly.
Home page of TikTok on Web.

AI deepfakes have become a headache for creators, and TikTok is finally stepping up to fight back. Social media consultant Matt Navarra spotted the platform quietly testing a new opt-in tool that hunts down AI-generated content mimicking a creator's face, giving them the power to flag it directly.

https://twitter.com/MattNavarra/status/2078129989128450064

Read more
You can now generate songs in your iMessage chats
iMessage users can now turn chats into short AI-generated songs
Text, Business Card, Paper

Suno has added an iMessage extension to its iOS app, letting users generate 30-second songs from voice recordings or typed prompts inside a Messages conversation.

The feature is available in the latest version of the Suno app and requires both people in the chat to have it installed. Users can access Suno from the plus menu in Messages, create a track, and share it without opening the standalone app.

Read more