
Before Facebook can even pay off the fine imposed on it by the FTC, it seems to have been hit by another Cambridge Analytica-!
Marketing company Hyp3r, which was found to be exploiting a security flaw to collect vast amounts of data, forced Facebook to ban it from its Instagram platform .
The loophole that Hyp3r exploited allowed it to aggregate the exact locations of millions of public posts. It also violated the terms of service by storing public stories and collecting data from public profiles (bio and followers).
Although the company did not collect any personal information, it was able to create detailed profiles of users without their permission. It also used this data to serve personalized ads to users.
Facebook strictly prohibits the use of “automated means” to collect data without its approval and does not share stories data through the official development framework.
Business Insider claims that after the Cambridge Analytica scandal, Hyp3r seemingly welcomed the restrictions on location tools and other features.
However, he secretly created a system that could bypass Facebook's restrictions and track Instagram's location information.
While Facebook promised to provide more privacy protections after the Cambridge Analytica debacle, this new incident highlights the company's weaknesses on this issue. What's even worse is that Hyp3r was part of Facebook's list of trusted marketing partners
In its defense, Hyp3r CEO Carlos Garcia says the company's marketing system was "compliant with consumer privacy regulations and the social network's terms of service.".
It also claims that Hyp3r never collected any private content, but it's rather hard to believe these claims, given that the company had access to stories after the 24-hour period that is visible on users' profiles.
Meanwhile, a Facebook spokesperson said that Hyp3r's actions were unauthorized and "violated our policies.".
