Equifax Move Over, Here Comes The Cambridge Analytica and Facebook Scandal!
By David Gamey - 20 Mar 2018.
We've been following security and breaches for a long time and they have been getting unquestionably worse. While mega-credit card breaches seem to have been falling off lately, other industries like healthcare, research analytics, and financial services have quickly taken their place. Last year was a record breaker for vulnerabilities and data breaches. We thought that Equifax was about as bad as it could get short of an all-out cyber-war. In light of recent events, that opinion now looks optimistic.
What Could Eclipse Equifax?
The big news that has emerged over the weekend and on Monday, March 19th is a breach or theft of data from Facebook by Strategic Communications Laboratories and Cambridge Analytica. It's not so much the scale of the breaches as Equifax is currently about 3 times larger. It is the very nature and exploitation of the breach/theft. If the reporting on this is accurate, this is far more disturbing than the neglect and apparent incompetence that led to the Equifax breach. The reporting not only hints at neglect and disinterest but carries strong suggestions of criminal activity. Currently, Facebook is aggressively investigating the incident and Cambridge have denied these claims.
What is certain at this point is that both Facebook and Cambridge need to do some serious explaining. It's not just that Cambridge took the data but also that Facebook appears to have known and been less than forthcoming about what they knew. There will be multiple inquiries and investigations in many countries. There will also be lawsuits and possibly criminal trials; as well as calls to put limits on tech companies or possibly break them up. Lastly, even if Facebook naively trusted a researcher who lied and cheated, there will be demands for changes.
Another thing that is certain is that Cambridge Analytica's role in the Brexit vote will raise questions in the UK. Their association with the Trump campaign in the 2016 US elections and connections to political figures like Steve Bannon, a one-time VP with Cambridge, and Donald Trump will further intrigue and add fuel to the already fragmented US political scene. Reporting indicates the Muller investigation will also be looking into Cambridge.
Finally, investigative journalists in the UK went undercover and have video of Cambridge executives talking about setting up opponents to look like they're corrupt or involved with prostitutes and leaking videos on the Internet. Cambridge is denying it, claiming it was a setup and that they were lured into a "hypothetical discussion."
Taken together and if accurate, Cambridge may have gone far beyond just targeting election ads. They may have actively manipulated and deceived the public. They may possibly be real "fake news."
Based on what has been reported to date, if accurate, we'd be surprised if Cambridge Analytica can survive as a company. Facebook too may be wounded even if it is too large to be killed. Even if the US doesn't take action against Facebook, other jurisdictions can. Several states with breach disclosure laws may act and the EU already has a tense relationship with Facebook.
One thing that is certain is that there is a lot more to this story and we will be hearing about it for a long time to come. What follows is a summary of news articles which should get you started. Keeping up on this will surely challenge everyone given the rate of new articles that keep appearing.
What Has Been Reported?
Cambridge Analytica, Strategic Communications Laboratories, and SCL Elections (all related) used a personality app to profile approximately 270K Facebook Users, using a further "loophole" they were able to gather information on another 50M users without asking for any consent, these were in turn used to generate over 30M psychographic profiles. The company has further been denying this for years.
- NYT in depth article 2018-3-17 https://www.nytimes.com/2018/03/17/us/politics/cambridge-analytica-trump-campaign.html
- Wired 2018-3-17 https://www.wired.com/story/cambridge-analytica-50m-facebook-users-data
Facebook denies this was a breach, confirms that Cambridge stole it's data, and shuts out the whistle-blower, Strategic Communication Laboratories, and Cambridge Analytica
- 2018-3-18 https://www.theregister.co.uk/2018/03/18/facebook_confirms_cambridge_analytica_stole_its_data_its_a_plot_claims_former_director/
- 2018-3-19 https://www.databreachtoday.com/facebook-attempts-to-explain-data-leak-denies-breach-a-10725
- 2018-3-19 https://www.theregister.co.uk/2018/03/19/facebook_suspends_account_of_cambridge_analytica_whistleblower_chris_wylie/
- 2018-3-19 Candian whistleblower in Cambridge Analytica scandal http://www.cbc.ca/news/politics/christopher-wylie-canada-libeals-cambridge-analytica-1.4582190
-
Cambridge Executives, including CEO Alexander Nix, caught on video discussing extortion, entrapment, and fake news
-
Several investigations are in progress including Massachusetts, UK prime minister's office, the EU,
- 2018-3-18 https://www.nytimes.com/2018/03/18/us/cambridge-analytica-facebook-privacy-data.htm
- 2018-3-19 https://www.theguardian.com/technology/2018/mar/19/no-10-very-concerned-over-facebook-data-breach-by-cambridge-analytica
- 2018-3-20 UK asks Facebooks' auditors asked to to stand down on Cambridge http://money.cnn.com/2018/03/19/technology/cambridge-analytica-audit/index.html 2018-3-20 UK issues emergency data seizure order https://www.theregister.co.uk/2018/03/19/boom_cambridge_analytica_explodes_following_extraordinary_tv_expose/
- 2018-3-20 Amid backlash the probes are underway https://www.databreachtoday.com/probes-begin-as-facebook-slammed-by-data-leak-blowback-a-10728
- 2018-3-19 UK Information Commissioner seeks warrant http://www.bbc.co.uk/news/technology-43465700
- 2018-3-19 Market reaction to the news was swift and sever with Facebook dropping almost $40B in trading Monday https://www.pymnts.com/facebook/2018/facebook-consumer-data-stock-market/
- Cambridge has contradicted itself on it's assitance to Leave.EU http://www.businessinsider.com/cambridge-analytica-has-contradicted-itself-on-its-work-for-leaveeu-2018-3
- 2018-3-20 Whistleblower talks about Cambridge and Bannon testing Trump campaign messaging in 2014 http://money.cnn.com/2018/03/20/technology/facebook-data-scandal-deepens/index.html
Some background
- 2017-2-26 Cambridge and Robert Mercer backed Brexit https://www.theguardian.com/politics/2017/feb/26/us-billionaire-mercer-helped-back-brexit
- 2013-3-19 The FTC failed to enforce privacy consent orders on Facebook from 2011https://epic.org/2018/03/facebook-breach-highlights-fai.html
- Previous Muller request for Cambridge documents 2017-12-15 https://www.wsj.com/articles/mueller-sought-emails-of-trump-campaign-data-firm-1513296899
Not to be confused with ...
- 2018-1-3 Fusion GPS was the research company behind the Steele Dossier http://thehill.com/policy/national-security/367166-fusion-gps-co-founders-say-they-were-shocked-by-contents-of-steele
- 2017-6-19 The 198M voter record leak was attributed to Deep Root Analytics working for the Republican party https://www.darkreading.com/threat-intelligence/rnc-voter-data-on-198-million-americans-exposed-in-the-cloud/d/d-id/1329172