Last October, Instagram exposed personal data of some users accessible to some business accounts, according to Facebook reports.
There was evidently a mistake in Business Suite, the method used by advertisers and social media practitioners to handle several Facebook and Instagram corporate accounts, whereby if a Facebook business account was connected to an Instagram account, it became part of a test community in which the company operated and in which the failure occurred.
The mistake allowed businesses involved in the working group to have access to users' personal information only by sending them a direct message to Instagram. Among the details that was revealed was the e-mail address of the user-in the case that it was private information-and the date of birth of the user, the data that the business you talk with on Instagram does not have to obtain.
Details could be obtained regardless of whether the user's account was private or whether the Instagram message feature was disabled. The details could be collected from the business accounts that were part of the experiment.
The observation was made by a security researcher called Saugat Pokharel. He also repeated the bug by checking to show how easy it was to access the information. In doing so, he called Facebook, a corporation that gave him a payout for submitting bugs to the social network via its "Bug Bounty" scheme, close to that run by many other Internet businesses.
According to Facebook, the mistake was repeated for a brief period of time in the month of October and was promptly reversed, obtaining notice from Pokharel, but it did not confirm the number of accounts that could be affected.
