What you need to know
- The profiles of 235M TikTok, Instagram, and YouTube users have been exposed.
- A database without password protection was discovered containing all the information.
- It had been collected by a company called Deep Social and stored online without a password.
According to TNW:
A databased containing scraped data of nearly 235 million social media users from Instagram, TikTok, and YouTube was exposed without any password protection. It contained user information such as
- Contact info,
- Date of Birth,
- Email Address,
- Images and Content,
- Stats about followers.
Security researcher Bob Diachenko discovered not one, but three identical copies of the database on August 1. It belonged to a company called Deep Social, which doesn’t seem to exist anymore. All of the data is available freely to ANYONE with Internet access.
2.5 Billion Data Privacy Class Action
Meanwhile in Europe, 2.5 Billion Data Privacy Class Action as documents claiming the company has harvested the data of users under 13 without consent, then sold it to advertising companies in breach of both UK and EU law, have been lodged with the High Court.
Not intended for those under 13
What is very interesting is YouTube’s response. One of its arguments is that the main YouTube platform is not intended for those under 13, who should be using the YouTube Kids app, which incorporates more safeguards.
This is the advice we have tried to afford parents for many years. At least now even YouTube have been put in a position whereby YouTube are stating this as fact themselves.
The case, which was lodged in July and is the first of its kind in Europe, is being brought by privacy campaigner Duncan McCann. If successful, he believes damages of just £500 would be payable to those whose data was breached.
‘That is still a problem, but we should also be aware of how the internet is using children, which was not the case ten years ago. Are we comfortable with children being products of the internet rather than products of their parents?’
Mr McCann, 41, will argue that YouTube and Google have breached both the UK’s Data Protection Act and the EU’s General Data Protection Regulations (GDPR).