"Largest Data Leak in History"

Quick Overview

Researchers demonstrated that a flaw in WhatsApp's phone number enumeration feature allowed them to scrape a dataset of 3.5 billion records, including phone numbers, profile pictures, and public keys, constituting what they called the largest data leak in history, which they responsibly disclosed to Meta before publishing.

Key Points: Researchers created a dataset of 3.5 billion WhatsApp records, which they assert would be the largest data leak in history if publicly released, containing phone numbers, timestamps, profile pictures, and public keys. The data enumeration was achieved by exploiting a basic security flaw in WhatsApp that allows users to look up someone using just a phone number, bypassing effective rate limiting. The scraping process was conducted from a single physical machine and IP address, achieving a rate of 100 million phone numbers per hour. The researchers found that roughly half of the numbers disclosed in the 2021 Facebook data leak were active on WhatsApp, underlining the continued exposure risk. The study also highlighted that users often share links to external profiles (like LinkedIn) in their 'About' text field, which can be correlated to enrich profiles and increase doxxing risks, sometimes revealing government/military affiliations. The researchers engaged in responsible disclosure, reporting the vulnerability to Meta on September 5, 2024, and later threatening publication before Meta implemented fixes. The video also contrasts this with the massive scale of operations by North Korean Lazarus Group hackers, who use similar tactics (like temporary SIM cards via GoGetSMS) to fund illicit activities, seizing 1,200 SIM-box devices worth €2.4 million.

Context: This video discusses a significant security research finding concerning WhatsApp's phone number enumeration feature, which allowed researchers to scrape an enormous dataset of user information. The context shifts to discuss how cybercriminals, specifically North Korean state-sponsored groups like Lazarus, exploit similar identity verification mechanisms (like temporary SMS services) to create fake accounts for massive fraud operations, such as those targeting cryptocurrency exchanges and Western companies.

Raw markdown version of this recap