# "Largest Data Leak in History"

Source: https://www.youtube.com/watch?v=ByfvX1z0u-I
Recap page: https://rapidrecap.app/video/ByfvX1z0u-I
Generated: 2025-11-21T19:34:55.643+00:00

---
## Quick Overview

Researchers demonstrated that a flaw in WhatsApp's phone number enumeration feature allowed them to scrape a dataset of 3.5 billion records, including phone numbers, profile pictures, and public keys, constituting what they called the largest data leak in history, which they responsibly disclosed to Meta before publishing.

**Key Points:**
- Researchers created a dataset of 3.5 billion WhatsApp records, which they assert would be the largest data leak in history if publicly released, containing phone numbers, timestamps, profile pictures, and public keys.
- The data enumeration was achieved by exploiting a basic security flaw in WhatsApp that allows users to look up someone using just a phone number, bypassing effective rate limiting.
- The scraping process was conducted from a single physical machine and IP address, achieving a rate of 100 million phone numbers per hour.
- The researchers found that roughly half of the numbers disclosed in the 2021 Facebook data leak were active on WhatsApp, underlining the continued exposure risk.
- The study also highlighted that users often share links to external profiles (like LinkedIn) in their 'About' text field, which can be correlated to enrich profiles and increase doxxing risks, sometimes revealing government/military affiliations.
- The researchers engaged in responsible disclosure, reporting the vulnerability to Meta on September 5, 2024, and later threatening publication before Meta implemented fixes.
- The video also contrasts this with the massive scale of operations by North Korean Lazarus Group hackers, who use similar tactics (like temporary SIM cards via GoGetSMS) to fund illicit activities, seizing 1,200 SIM-box devices worth €2.4 million.

![Screenshot at 00:00: A slide highlighting the research finding that the scraped dataset contained 3.5 billion records, described as the 'largest data leak in history' if released.](https://ss.rapidrecap.app/screens/ByfvX1z0u-I/00-00-00.png)

**Context:** This video discusses a significant security research finding concerning WhatsApp's phone number enumeration feature, which allowed researchers to scrape an enormous dataset of user information. The context shifts to discuss how cybercriminals, specifically North Korean state-sponsored groups like Lazarus, exploit similar identity verification mechanisms (like temporary SMS services) to create fake accounts for massive fraud operations, such as those targeting cryptocurrency exchanges and Western companies.

## Detailed Analysis

The video details a study revealing a vulnerability in WhatsApp that allowed researchers to enumerate and scrape 3.5 billion user records, including phone numbers, profile pictures, and public keys, a scale they termed the 'largest data leak in history' (00:00). This was possible because WhatsApp allows users to look up any phone number to see if they are on the platform, and the researchers bypassed rate limiting to achieve 100 million lookups per hour from a single machine (01:08, 02:47). The research also uncovered that users often link external profiles in their 'About' section, leading to potential doxxing, especially for government or military personnel (01:54). Following responsible disclosure, Meta implemented fixes (03:01). The video then pivots to show how similar phone number validation flaws are exploited by criminal enterprises, specifically highlighting 'SIM Cartel' operations involving thousands of SIM boxes used to create millions of illegal accounts for various scams like investment fraud and daughter-son scams (05:21, 06:27). The raid on a SIM farm seized 1,200 SIM-box devices valued at €2.4 million (06:44). Finally, the video touches upon North Korean Lazarus Group hackers using similar tactics, including identity theft and fake remote workers with VPNs/AI filters, to fund weapons programs (07:01, 09:00).

### WhatsApp Enumeration Flaw

- Exploit allowed phone number lookup bypassing rate limiting
- Achieved 100 million lookups per hour from one IP address
- Dataset included 3.5B records: phone numbers, profile pictures, public keys

### Data Exposure Risks

- Nearly half of 2021 Facebook data leak numbers were active on WhatsApp
- Users share external links in 'About' text, risking doxxing of government employees

### SIM Cartel Operation

- Raid seized 1,200 SIM-box devices operating 40,000 SIM cards
- Seizures included 4 luxury vehicles and €431,000 in frozen bank accounts

### Scam Operations Enabled by SIM Farms

- GoGetSMS service used for account creation on platforms like WhatsApp, Tinder, and Facebook
- Perpetrators use SIM farms to churn numbers for scams like daughter-son scams and investment fraud

### North Korean Hacking Context

- Lazarus hackers use similar tactics (identity loaning, fake remote work profiles with AI filters) to fund weapons programs
- Interview highlights North Korean operatives posing as Mexican workers

![Screenshot at 00:00: A slide highlighting the research finding that the scraped dataset contained 3.5 billion records, described as the 'largest data leak in history' if released.](https://ss.rapidrecap.app/screens/ByfvX1z0u-I/00-00-00.png)
![Screenshot at 01:11: A table showing the breakdown of phone numbers scraped by country code, with a total of 63.17B 'Candidates \(pp\)' after post-processing.](https://ss.rapidrecap.app/screens/ByfvX1z0u-I/00-01-11.png)
![Screenshot at 05:22: A close-up of one of the seized SIM bank devices, labeled G4 and G5, showing slots for numerous SIM cards.](https://ss.rapidrecap.app/screens/ByfvX1z0u-I/00-05-22.png)
![Screenshot at 06:54: A summary slide detailing the results of the law enforcement action, including 5 arrests, seizure of 1200 SIM-box devices, and €431,000 frozen in bank accounts.](https://ss.rapidrecap.app/screens/ByfvX1z0u-I/00-06-54.png)
![Screenshot at 09:00: A composite image illustrating North Korean operatives using fake backgrounds \(like an office environment\) during video interviews to conceal their true working conditions \(laundry drying in the workspace\).](https://ss.rapidrecap.app/screens/ByfvX1z0u-I/00-09-00.png)
