[Breaches](/breaches)

Losing Face: Two More Cases of Third-Party Facebook App Data Exposure

[Blog](/blog)[Breaches](/breaches)[Resources](/resources)[News](/news)

# Losing Face: Two More Cases of Third-Party Facebook App Data Exposure

##### [UpGuard Team](/team/upguard)

Published Apr 03, 2019

##### Join 27,000+ cybersecurity newsletter subscribers

The UpGuard [Cyber Risk](/blog/cybersecurity-risk) team can now report that two more third-party developed Facebook app datasets have been found exposed to the public internet. One, originating from the Mexico-based media company [Cultura Colectiva](https://culturacolectiva.com/en/), weighs in at 146 gigabytes and contains over 540 million records detailing comments, likes, reactions, account names, FB IDs and more. This same type of collection, in similarly concentrated form,[ has been cause for concern in the recent past](https://www.theguardian.com/technology/2018/mar/17/facebook-cambridge-analytica-kogan-data-algorithm), given the potential uses of such data.

A separate backup from a Facebook-integrated app titled “At the Pool” was also found exposed to the public internet via an Amazon S3 bucket. This database backup contained columns for fk\_user\_id, fb\_user, fb\_friends, fb\_likes, fb\_music, fb\_movies, fb\_books, fb\_photos, fb\_events, fb\_groups, fb+checkins, fb\_interests, password, and more. The passwords are presumably for the “At the Pool” app rather than for the user’s Facebook account, but would put users at risk who have reused the same password across accounts.

The At the Pool discovery is not as large as the Cultura Colectiva dataset, but it contains plaintext (i.e. unprotected) passwords for 22,000 users. At the Pool ceased operation in 2014 (last non-redirect web archived capture[ here](https://web.archive.org/web/20140517020839/http:/atthepool.com/)), and even the parent company’s website is currently returning a 404 error notice. This should offer little consolation to the app’s end users whose names, passwords, email addresses, Facebook IDs, and other details were openly exposed for an unknown period of time. 

Each of the data sets was stored in its own [Amazon S3 bucket](https://www.upguard.com/blog/check-your-amazon-s3-permissions-someone-will) configured to allow public download of files.

The data sets vary in when they were last updated, the data points present, and the number of unique individuals in each. What ties them together is that they both contain data about Facebook users, describing their interests, relationships, and interactions, that were available to third party developers. As Facebook faces scrutiny over its data stewardship practices, they have made efforts to reduce third party access. But as these exposures show, the data genie cannot be put back in the bottle. Data about Facebook users has been spread far beyond the bounds of what Facebook can control today. Combine that plenitude of personal data with storage technologies that are often misconfigured for public access, and the result is a long tail of data about Facebook users that continues to leak.

## Incident Response

These two separate discoveries demonstrated two polar opposite ends of the spectrum when it comes to the ease, or difficulty, of seeing them secured. With regard to the Cultura Colectiva data, our first notification email went out to Cultura Colectiva on January 10th, 2019. The second email to them went out on January 14th. To this day there has been no response.

Due to the data being stored in Amazon’s S3 cloud storage, we then notified Amazon Web Services of the situation on January 28th. AWS sent a response on February 1st informing us that the bucket’s owner was made aware of the exposure.

When February 21st rolled around and the data was still not secured, we again sent an email to Amazon Web Services. AWS again responded on that same day stating they would look into further potential ways to handle the situation.

It was not until the morning of April 3rd, 2019, after Facebook was contacted by Bloomberg for comment, that the database backup, inside an AWS S3 storage bucket titled “cc-datalake,” was finally secured.

On the flip side of the coin, the data stemming from “At the Pool” had been taken offline during the time UpGuard was looking into the likely data origin, and prior to a formal notification email being sent. It is unknown if this is a coincidence, if there was a hosting period lapse, or if a responsible party became aware of the exposure at that time. Regardless, the application is no longer active and all signs point to its parent company having shut down.

## Conclusion

These two situations speak to the inherent problem of mass information collection: the data doesn’t naturally go away, and a derelict storage location may or may not be given the attention it requires.

For app developers on Facebook, part of the platform’s appeal is access to some slice of the data generated by and about Facebook users. For Cultura Colectiva, data on responses to each post allows them to tune an algorithm for predicting which future content will generate the most traffic. The data exposed in each of these sets would not exist without Facebook, yet these data sets are no longer under Facebook’s control. In each case, the Facebook platform facilitated the collection of data about individuals and its transfer to third parties, who became responsible for its security. The surface area for protecting the data of Facebook users is thus vast and heterogenous, and the responsibility for securing it lies with [millions](https://www.adweek.com/digital/facebook-platform-supports-more-than-42-million-pages-and-9-million-apps/) of app developers who have built on its platform.

## How UpGuard can help detect and prevent data breaches and data leaks

UpGuard helps security teams proactively detect and shut down data breach risks that[ impact their internal security posture](https://www.upguard.com/product/breach-risk) and the security postures[ of all third-party relationships](https://www.upguard.com/product/vendorrisk).

[UpGuard can also continuously monitor the open, deep, and dark web](https://www.upguard.com/product/breach-risk/threat-monitoring), discovering stolen credentials and leaked data before they're weaponized. Its AI Threat Analyst acts as a virtual Tier 1 analyst, filtering out noise and elevating only high-confidence threats from sources like malware logs, ransomware leak sites, and encrypted messaging platforms. 

The resulting significant reduction in false positives equips security teams to execute fast and targeted responses on risks that actually matter.

## Protect your organization

Get in touch or book a free demo.

[Contact sales](/demo)

[Free demo](/demo)

## Related breaches

Learn more about the latest issues in cybersecurity.

[](/breaches/cyber-risks-of-the-2026-world-cup)

#### [Own Goal: Inside the Cyber Risks of the 2026 World Cup](/breaches/cyber-risks-of-the-2026-world-cup)

Free World Cup streams and black-market betting sites are leaking fan data. UpGuard research reveals the hidden cyber risks of the 2026 tournament.

[](/team/greg-pollock)

[Greg Pollock](/team/greg-pollock)

June 30, 2026

[](/breaches/social-insecurity-billions-of-social-security-number-and-passwords)

#### [Social Insecurity: Billions of Social Security Number and Passwords](/breaches/social-insecurity-billions-of-social-security-number-and-passwords)

UpGuard research found a trove of sensitive information in an exposed Elastic database. Getting to the bottom of what it meant led us down an interesting path.

[](/team/greg-pollock)

[Greg Pollock](/team/greg-pollock)

February 18, 2026

[](/breaches/angelsense-data-leak)

#### [Sixth Sense: GPS and AI Data Exposed for Assistive Devices](/breaches/angelsense-data-leak)

UpGuard can now report that it has secured an Elasticsearch database for AngelSense, a GPS tracker for children and adults with special needs.

[](/team/upguard)

[UpGuard Team](/team/upguard)

January 30, 2025

[](/breaches/pta-database)

#### [Stolen Data: National PTA Database Available on Dark Web](/breaches/pta-database)

On May 13th, UpGuard discovered a new set of data recently posted on a prominent dark web forum, this time allegedly belonging to the National Parent Teacher Association.

[](/team/upguard)

[UpGuard Team](/team/upguard)

May 14, 2024

[](/breaches/smarterselect)

#### [Student Applications: How an Education Software Company Exposed Millions of Files](/breaches/smarterselect)

UpGuard can now report that a public Google Cloud Storage bucket containing approximately 1.5 terabytes of data used to administer funding programs for college students has been secured. The bucket belonged to SmarterSelect, a company that provides software for managing the application process for scholarships, grants, and awards. The more than 2.8 million files included documents like transcripts, resumes, personal essays, tax returns, and invoices for approximately 1.2 million applications to funding programs.

[](/team/upguard)

[UpGuard Team](/team/upguard)

November 22, 2021

[](/breaches/power-apps)

#### [By Design: How Default Permissions on Microsoft Power Apps Exposed Millions](/breaches/power-apps)

38 million records were exposed in multiple data leaks resulting from misconfigured Microsoft Power Apps portals. Data included sensitive information such as COVID-19 contact tracing data, COVID-19 vaccination appointments, social security numbers for job applicants, employee IDs, and millions of names and email addresses.

[](/team/upguard)

[UpGuard Team](/team/upguard)

August 23, 2021

[View all breaches](/breaches)

### Sign up for our newsletter

UpGuard's monthly newsletter cuts through the noise and brings you what matters most: our breaking research, in-depth analysis of emerging threats, and actionable strategic insights.

##### Free instant security score

## How secure is your organization?

Request a free cybersecurity report to discover key risks on your website, email, network, and brand.

* Instant insights you can act on immediately
* Hundreds of risk factors including email security, SSL, DNS health, open ports and common vulnerabilities

[Free score](/instant-security-score)
