Facebook quietly discloses another serious privacy breach

Over 100 developers may have had improper access to user data, the company revealed.
 By 
Caitlin Welsh
 on 
Original image replaced with Mashable logo

As many as 100 developers may have had improper access to Facebook user data due to an oversight in the way permissions were revoked, according to a post on the company's developer blog on Tuesday.

The names and profile pictures of people in certain Groups on the platform, linked with their activity in those Groups, were still accessible to some software developers — despite the company changing access parameters back in April 2018, Facebook's director of platform's partnerships Konstantinos Papamiltiadis wrote.

Of the "roughly 100 partners" who had retained user data access through the Groups API over the past 18 months, "at least 11 partners accessed group members' information in the last 60 days," the post said.

The changes were supposed to work as follows:

"Before April 2018, group admins could authorize an app for a group, which gave the app developer access to information in the group. But as part of the changes to the Groups API after April 2018, if an admin authorized this access, that app would only get information, such as the group’s name, the number of users, and the content of posts. For an app to access additional information such as name and profile picture in connection with group activity, group members had to opt-in."

April 2018, you say? Yes, this was one of the changes made in the wake of the Cambridge Analytica revelations in March last year, as part of the company's promise to clean up its policies and practices around user data and who has access to it.

Most recently, in September this year, Facebook suspended "tens of thousands" of apps from the platform for unspecified reasons.

While Facebook says it's asked the developers concerned to delete any information they've retained and will perform "audits" to ensure follow-through, the post didn't specify which groups were affected, how many users' data was accessed, how many times, or which developers were involved. And unlike the app suspension news, this disclosure was made on the For Developers blog, not the more public-facing Newsroom.

Facebook assures users — or at least developers — that they're aware of "no evidence of abuse" of this data. But given this news, it's hard not to wonder what else they've missed.

Mashable Image
Caitlin Welsh

Caitlin is Mashable's Australian Editor. She has written for The Guardian, Junkee, and any number of plucky little music and culture publications that were run on the smell of an oily rag and have since been flushed off the Internet like a dead goldfish by their new owners. She also worked at Choice, Australia's consumer advocacy non-profit and magazine, and as such has surprisingly strong opinions about whitegoods. She enjoys big dumb action movies, big clever action movies, cult Canadian comedies set in small towns, Carly Rae Jepsen, The Replacements, smoky mezcal, revenge bedtime procrastination, and being left the hell alone when she's reading.

Mashable Potato

Recommended For You

Instagram denies data breach: So what's up with those sketchy change password emails?
instagram logo against a black background

Panera Bread breach: ShinyHunters claims hack of 14 million customers' data
Panera Bread logo on storefront

See Samsung Galaxy S26's Privacy Display feature in action
galaxy s25 ultra phone on display at galaxy unpacked launch event

Moltbook is a 'security nightmare' waiting to happen, expert warns
moltbook website appears on phone screen

More in Tech
How to watch Chelsea vs. Port Vale online for free
Alejandro Garnacho of Chelsea reacts

How to watch 'Wuthering Heights' at home: Margot Robbie and Jacob Elordi's controversial romance now streaming
Margot Robbie and Jacob Elordi embracing in still from "Wuthering Heights"

How to watch New York Islanders vs. Philadelphia Flyers online for free
Matthew Schaefer of the New York Islanders warms up

How to watch Mexico vs. Belgium online for free
Israel Reyes of Mexico reacts

How to watch Brazil vs. Croatia online for free
Vinicius Junior #10 of Brazil leaves

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!