The recent revelation that nearly 50 million Facebook users’ accounts were compromised by an attack that gave hackers the ability to take over those accounts is the latest data security scare for the social media giant.
By: Phil Gladwell
News, info & events

Earlier this year, CEO Mark Zuckerberg was grilled about the alleged data mining of as many as 87 million users by Cambridge Analytica which raised concerns about the personal information stored on Facebook and which prompted changes to its privacy policy in a bid to salvage its reputation.
With these significant security issues, you’d be forgiven for thinking that Facebook had suffered significant consequences in terms of losing the confidence of its users and closed accounts. However, it seems that’s not the case. While investors are impacting the Facebook share price, there’s no sign of a wholesale desertion by those who share their daily lives, and data, as account holders. According to a report by Goldman Sachs, Facebook’s usage following the Cambridge Analytica scandal actually increased with US unique users rising by 7% year on year in April, and Zuckerberg claimed earlier this year that an inconsequential number of users deleted their accounts as a result of the data scandal.
After the most recent incident, we at EnterpriseRed ran a Twitter poll asking if users had deleted their accounts as a direct result, with 62% of those responding saying no. It seems that, once again, Facebook are surviving the security storm.
It can happen to anyone
The Facebook data scandal was not the only incident to happen this year with companies such as Ticketmaster, Uber, Delta, Under Armour, Superdrug, Reddit and, most recently, British Airways falling into the line of fire.
The latter had to apologise to customers for what they called a “sophisticated, malicious criminal attack” on its website which affected around 380,000 transactions, resulting in personal and financial details of customers making or changing bookings being compromised.
Again, EnterpriseRed ran a Twitter poll following the news, with 43% of respondents confirming that the breach would lead to them having reservations about flying with the airline in future.
However, while customers express concern in the immediate aftermath of security incidents, there is no concrete evidence to show that consumers are worried enough to avoid giving custom to those businesses involved.

It begs the question, therefore, whether people actually care about the security and privacy of their data. Perhaps the seemingly constant stream of news stories is simply desensitising them to the potential consequences of their data being lost or stolen.
So, why should consumers care?
The biggest, long-term threat of a data breach is identity theft, which can have devastating consequences. Maybe having to cancel a bank card if account details have been compromised is a short term inconvenience, but the risks don’t stop there. By gathering information such as someone’s name, date of birth and national insurance number, a fraudster could cause long term and ongoing chaos given those details never change and are commonly used to prove identity. Such data can be sold by hackers to fraudsters who take out loans and build up debts which may not even become clear to the victim until they need to borrow money, perhaps, or take out a mortgage. Only then might they realise the extent of the problem the theft of their data has caused and it can take months or even years to unravel and recover.
Identity theft is a real threat – a stolen passport landed one British couple with a huge demand from a German taxman who wouldn’t back down.
Even if a hacker has simply gained access to bank accounts or credit cards then this can leave people unable to pay everyday living costs, which happened to this individual who found himself a victim of a phishing attack.
The frequency and severity of security incidents shows that hackers are relentless in their quest to steal personal information, whether for financial gain or other motives.
Organisations have a legal and moral obligation to do everything in their power to protect their customers, but don’t customers also have a role to play in protecting themselves – by asking organisations who ask for their data how they’re going to use it, how they’ll protect it from loss or theft and who they might share it with?
And in the event that those organisations are found to be at fault for security breaches, perhaps customers need to vote with their feet, sending a clear message to those organisations, and all others, that they will only deal with businesses who take every possible step to protect their data.